









 |
W32/Amca Worm
| Name |
W32/Amca Worm |
| Aliases |
W32.Amca |
| Discovered on |
June 29, 2007 |
Virus Information - W32/Amca Worm:
W32/Amca is a worm. The worm will infect Windows systems and spreads through removable drives.
The worm will arrive as a dropped file from the network or removable drive.
Upon execution, the worm copies itself as PAC.EXE, KMON.OCX, ACD.CMD, KTKBDHK3.DLL, lil11.dll, scrrntr.dll, MSWINSCK.OCX and ACD2.CMD in the Windows System folder.
The worm modifies registry at the following location to load itself during each startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
It also copies activexdebugger32.exe and Autorun.inf in the removable drives.
The worm also has backdoor capabilities, allowing the remote attacker to get access to the infected computer.
The worm capable of gathering sensitive information from the infected computer and send it to remote attacker via email.

|