









 |
W32/P2P.Malas.H Worm
| Name |
W32/P2P.Malas.H Worm |
| Aliases |
Win32.Worm.P2P.Agent.AM, P2P-Worm.Win32.Malas.h, W32/Autorun.OM.worm, Worm.Khanani.A |
| Discovered on |
April 25, 2008 |
Virus Information - W32/P2P.Malas.H Worm:
W32/P2P.Malas.H is a worm. The worm will infect Windows systems and spreads through shared drives.
Upon execution, the worm drops the following files:
OfficeUpdate.exe in the Windows\Web folder,
svchost.exe in the Current User 'sTemp folder,
MSshare.exe in the Program Files\Common Files\Microsoft Shared folder,
AdobeUpdate.exe in the %ALL Users% Startup folder,
SexGame.exe in the Program Files\XPCode folder,
SexScreenSaver.scr in the Program Files\XPCode folder,
autoply.exe in the Root of all drives,
Autorun.inf in the Root of all drives.
The trojan modifies the registry at the following location to load itself during each startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SoundMax
It also modifies the registry at the following location:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lanmanserver\Shares\New_soft

|