Home Malware Programs Worms M32/Blaster.worm

M32/Blaster.worm

Posted: May 10, 2011

M32/Blaster.worm is a malicious worm program that carries a variable payload. M32/Blaster.worm is related to spyware that offers information according to which relevant adjustments are made in line with the algorithm of the M32/Blaster.worm. M32/Blaster.worm successfully propagates using removable and network drives. M32/Blaster.worm is able to replicate itself from affected PCs to network drives and removable drives. A further copy of the M32/Blaster.worm is generated when the network or pen drive or another external source data is copied by unwary computer users to their PC systems.

That's why removal of M32/Blaster.worm also refers to network and external sources, and is even more dangerous, as the M32/Blaster.worm is basically an infection that propagates from external drive to internal drive, for example, from network to computer system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ALLUSERSPROFILE%\Documents\Server\shhlp.dll
    2 \hlp.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\HKEY..\..\..\..{RegistryKeys}"AppSecDll" = "%system%\mshlps.dll""LoadAppInit_DLLs" = 1Session Manager\AppCertDlls]Windows][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\
Loading...