Threat Database Worms Worm.Win32.WBNA.aot

Worm.Win32.WBNA.aot

By GoldSparrow in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 169
First Seen: August 23, 2011
Last Seen: November 9, 2020
OS(es) Affected: Windows

Worm.Win32.WBNA.aot is a dangerous worm that copies itself to spread from one computer system to another and runs as a hidden background process to bypass the detection of security programs. Worm.Win32.WBNA.aot uses malicious tricks to download harmful malware items from the web. Worm.Win32.WBNA.aot opens up firewalls and gathers personal information and transmits it to remote hackers. It is strongly recommended to remove Worm.Win32.WBNA.aot as quickly as possible to protect your computer.

File System Details

Worm.Win32.WBNA.aot may create the following file(s):
# File Name Detections
1. %AppData%\cnqsm.exe
2. %AppData%\manager.exe
3. %AppData%\5ykq.log

Registry Details

Worm.Win32.WBNA.aot may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Local Account Authority Service\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database
HKEY_LOCAL_MACHINE\SOFTWARE\tgs90gv74r
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Local Account Authority Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\cnqsm\DEBUG
HKEY_LOCAL_MACHINE\SOFTWARE\skd3uf1wbd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWSAPAGENT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWSAPAGENT\0000\Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\cnqsm
HKEY_LOCAL_MACHINE\SOFTWARE\f6h45yhjqa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWSAPAGENT

Trending

Most Viewed

Loading...