Home Malware Programs Worms IM Worm.Win32.Sohanad.bm

IM Worm.Win32.Sohanad.bm

Posted: April 20, 2011

IM-Worm.Win32.Sohanad.bm is one of the most dangerous computer threats. Once IM-Worm.Win32.Sohanad.bm computer worm will run automatically when Windows operating system boots up. Therefore, it is very difficult to manually detect and remove IM-Worm.Win32.Sohanad.bm. When executed, M-Worm.Win32.Sohanad.bm may drop malicious files into Windows registry and flow the desktop with unwanted pop-up alerts. M-Worm.Win32.Sohanad.bm is a crucial security and privacy threat. Remove M-Worm.Win32.Sohanad.bm immediately from your computer system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\RVHOST.exe
    2 %System%\setting.ini
    3 %Windir%\RVHOST.exe
    4 %Windir%\Tasks\At1.job
    5 %Windir%\Tasks\At2.job

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\SystemHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XTray.exe
Loading...