Home Malware Programs Trojans Boot.Alworo

Boot.Alworo

Posted: July 12, 2011

Boot.Alworo is a damaging computer MBR(Master Boot Record) Trojan, which is sophisticated enough to assure its completely undetected invasion into your computer system. Boot.Alworo would load malware threats from the hard drive as well as the original MBR. Boot.Alworo can change the original MBR which will lead to damage to your PC system. Boot.Alworo will find the right backdoors on your PC to enter the system and start performing its malicious activities. Remove Boot.Alworo from your machine as soon as possible.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\cmd.exe
    2 %System%\mmc.exe
    3 %System%\taskmgr.exe
    4 %Windir%\system.ini
    5 Jqyfub.exe
    6 userinit.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\ApcrmkehHKEY_CURRENT_USER\Software\Apcrmkeh\-72398023HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\SvcHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] UacDisableNotify = 0?00000001HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Loading...