Home Malware Programs Worms W32.Ackantta.H@mm

W32.Ackantta.H@mm

Posted: October 8, 2010

W32.Ackantta.H@mm is an email worm which spreads by raiding a compromised computer and using the internet to mass-mail itself. W32.Ackantta.H@mm steals email contact details from the address list before sending itself to other users. W32.Ackantta.H@mm has the ability to bypass average computer security applications and should be terminated using a reliable malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 Dm28sf0V@XK$NX8hOu
    2 HPWuSchdj.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\HP35HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\"hke8" = "[STRING]"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\"hke9" = "[STRING]"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"HP Software Updater v1.4" = "[PATH TO EXECUTABLE]"HKEY_LOCAL_MACHINE\Software\HP35HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"[PATH TO EXECUTABLE]"
Loading...