Home Malware Programs Worms W32.Zimuse

W32.Zimuse

Posted: January 26, 2010

W32.Zimuse is a malicious network-aware Worm which also spreads via removable media. W32.Zimuse can download other malicious applications referenced in autorun.inf files that may be located on removable drives or network drives. W32.Zimuse will try to spread to other computers and should be removed from the infected computer upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\\drivers\\Mseu.sys %System%\\drivers\\Mstart.sys %System%\\ainf.inf %System%\\mseus.exe %System%\\tokset.dll
    2 %System%\drivers\Mseu.sys %System%\drivers\Mstart.sys %System%\ainf.inf
    3 %System%\mseus.exe
    4 %System%\tokset.dll
    5 Dump.exe
    6 Iqtest.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSTARTHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MseuHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UnzipServiceHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Dump" = "C:\Program files\Dump\Dump.exe"
Loading...