Home Malware Programs Worms Malware.Spacefam

Malware.Spacefam

Posted: December 9, 2010

Malware.Spacefam is a network-aware computer worm that will attempt to replicate across an existing network. Malware.Spacefam also spreads using Windows networking APIs, MAPI functions or email clients such as Microsoft Outlook. Malware.Spacefam creates unknown email messages with corrupt attachments and sometimes attaches itself to outgoing email messages. Malware.Spacefam also uses a misleading message which suggests that the recipient should open the attachment to see something interesting or important. Malware.Spacefam should not be trusted and must be removed from the infected system once detected.

Aliases

Worm.SuspectCRC (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\mlf.exe
    2 %AppData%\xfdtc.exe
    3 %Temp%\1.tmp
    4 %Temp%\2.tmp
    5 %Temp%\4.tmp
    6 %Temp%\5.tmp
    7 %Windir%\Temp\3.tmp
    8 %Windir%\Temp\6.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\systems]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...