Wintoo, which is also known as Sexer, is a malicious worm that spreads via e-mail contained in messages that are infected with executable attachments. The email message and subject are in Russian. The Wintoo worm installs onto the users PC after it is executed and makes changes to the user's desktop background image. Wintoo will run on every Windows startup.

File System Details

Wintoo may create the following file(s):
# File Name Detections
1. win2drv.exe
2. sex.exe
3. kavutil.exe
4. sex.bmp
5. kavutil.bmp

Registry Details

Wintoo may create the following registry entry or registry entries:

