Generic.dx!sve
Generic.dx!sve is a computer worm that spreads on removable USB drives. Generic.dx!sve does this by creating an Autorun.Inf file on the root of each drive inserted to the compromised machine. Generic.dx!sve will run automatically if the affected drive is accessed, causing the targeted system endless problems.
Aliases
W32.Ircbrute
Worm:Win32/Hamweq.gen!C
Worm:Win32/Hamweq.gen!C
File System Modifications
- The following files were created in the system:
# File Name 1 %SystemDrive%\SYSTEM 2 %SystemDrive%\SYSTEM\S-1-5-(Varies) 3 %SystemDrive%\SYSTEM\S-1-5-(Varies)\Desktop.ini 4 %SystemDrive%\SYSTEM\S-1-5-(Varies)\system.exe 5 [Removable Drive]:\autorun.inf 6 [Removable Drive]:\SYSTEM 7 [Removable Drive]:\SYSTEM\S-1-5-(Varies 8 [Removable Drive]:\SYSTEM\S-1-5-(Varies)\Desktop.ini 9 [Removable Drive]:\SYSTEM\S-1-5-(Varies)\system.exe
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-21CX1C643131}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-21CX1C643131}\] "StubPath"= "%SystemDrive%\SYSTEM\S-1-5-(Varies)\system.exe"
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.