Home Malware Programs Worms Monikey

Monikey

Posted: March 28, 2006

Monikey is a rapidly spreading Internet worm, which propagates by e-mail and through file sharing networks.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 chkdskw.exe
    2 itstore.dll
    3 karnal32.dll
    4 mslogon.dll
    5 mstcpmon.exe
    6 mswshell.dll
    7 sfc32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTCLSID[randomnumer]InProcServer32(Default)=mswshell.exeHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionAppletsSysBackupHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWindowsAppInit_DLLs=karnal32.dllHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadShell=[randomnumber]
Loading...