Home Malware Programs Worms Generic.dx!sve

Generic.dx!sve

Posted: June 8, 2010

Generic.dx!sve is a computer worm that spreads on removable USB drives. Generic.dx!sve does this by creating an Autorun.Inf file on the root of each drive inserted to the compromised machine. Generic.dx!sve will run automatically if the affected drive is accessed, causing the targeted system endless problems.

Aliases

W32.Ircbrute
Worm:Win32/Hamweq.gen!C

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %SystemDrive%\SYSTEM
    2 %SystemDrive%\SYSTEM\S-1-5-(Varies)
    3 %SystemDrive%\SYSTEM\S-1-5-(Varies)\Desktop.ini
    4 %SystemDrive%\SYSTEM\S-1-5-(Varies)\system.exe
    5 [Removable Drive]:\autorun.inf
    6 [Removable Drive]:\SYSTEM
    7 [Removable Drive]:\SYSTEM\S-1-5-(Varies
    8 [Removable Drive]:\SYSTEM\S-1-5-(Varies)\Desktop.ini
    9 [Removable Drive]:\SYSTEM\S-1-5-(Varies)\system.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-21CX1C643131}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-21CX1C643131}\] "StubPath"= "%SystemDrive%\SYSTEM\S-1-5-(Varies)\system.exe"
Loading...