Home Malware Programs Worms W32.P2P.Tanked

W32.P2P.Tanked

Posted: March 28, 2006

W32.P2P.Tanked is a worm that tries to spread itself through the KaZaA and iMesh file-sharing networks. The worm also has a backdoor Trojan capability that allows a hacker to receive control over an infected PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cmd32.exe
    2 system32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunOnceDeletethevaluesSystemSASandCMDDeletethevaluescalledSystemSASandCMDHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices
Loading...