Home Malware Programs Worms W32.Mocon

W32.Mocon

Posted: January 21, 2011

W32.Mocon is a malicious worm that runs in the background and has threat characteristics of a ZBot banking Trojan. W32.Mocon disables the firewall and attempts to steal sensitive financial data like credit card numbers, and online banking login details. W32.Mocon creates a startup registry entries that load at boot of Windows. W32.Mocon is a malicious worm that may represent a severe security risk for the compromised system and/or its network environment and should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 C:\autorun.inf
    2 C:\cssrs.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Verificador do sistema" = "c:\cssrs.exe"
Loading...