Home Malware Programs Trojans W32.Sovtank

W32.Sovtank

Posted: January 24, 2008

W32.Sovtank is a virus of Trojan category that spreads by infecting executable files. As soon as it is executed W32.Sovtank will update your desktop background with the image related to the former Soviet Union symbol (a sickle and a hammer in a red background). W32.Sovtank can also reduce security settings making your computer vulnerable to malware applications and remote hackers.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [CURRENT BACKGROUND IMAGE FOLDER]\ussr_[6 RANDOM LETTERS].bmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Loading...