Home Malware Programs Worms Malware.Gammima!rem

Malware.Gammima!rem

Posted: December 14, 2010

Malware.Gammima!rem is a worm which is spread by attackers through removable media. Malware.Gammima!rem enables cyber criminals to get access and full control over the targeted computers. Malware.Gammima!rem is executed whenever the user opens a corrupted storage tool. Malware.Gammima!rem stealthily installs itself into the computer system and runs a payload. Malware.Gammima!rem surveys Internet Explorer windows in order to steal account details and other personal information associated with the MapleStory online game. Malware.Gammima!rem sends gathered data to a predestined website and inserts its code into every active system process. Therefore, the worm runs constantly. Remove it immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\cvasds1.dll
    2 %Temp%\cvasdso.dll
    3 %Temp%\herss.exe
    4 c:\autorun.inf
    5 c:\rg9g9bgq.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
Loading...