Home Malware Programs Worms Slogod.AT

Slogod.AT

Posted: November 25, 2008

Slogod.AT, also known as VBS/Slogod.AT, is an annoying hostile worm that spreads by making copies of itself to every removable drive that it can locate. Slogod.AT maliciously attacks your PC's system settings. Slogod.AT disables System Restore and Autoplay settings for drives. Slogod.AT can also stop you from using the Command Prompt and disrupts local searches. Slogod.AT may modify and change your mouse settings so that they become almost inoperative. Slogod.AT can remove "Recently opened documents" and "Documents" shortcuts from your Start Menu. Files from your Recycle Bin can be deleted and the "File" menu can be removed from all the folders.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\twunk32.txt
    2 cradle_of_filthe.vbe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "%System%\userinit.exe,%System%\wscript.exe %System%\cradle_of_filthe.vbe"
Loading...