Home Malware Programs Worms W32/Xirtem@MM

W32/Xirtem@MM

Posted: November 24, 2010

W32/Xirtem@MM is a mass mailing worm that poses a threat to PC security and shouldbe removed immediately. W32/Xirtem@MM also spreads through removable media using autorun.inf, and also by copying itself to Shared folders of Peer-2-Peer applications. Do not give W32/Xirtem@MM a chance to spread. Terminate it immediately using a reliable malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\SystemProc\lsass.exe
    2 %ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
    3 %ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
    4 %ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ERSvc\Start = 0x00000004
Loading...