WORM_STUXNET.A
WORM_STUXNET.A is a computer worm that spreads on removable USB drives. WORM_STUXNET.A does this by creating an Autorun.Inf file on the root of each drive inserted to the compromised machine. WORM_STUXNET.A will run automatically if the affected drive is accessed, causing the targeted system endless problems.
File System Modifications
- The following files were created in the system:
# File Name 1 %System%\drivers\mrxcls.sys - detected as RTKT_STUXNET.A 2 %System%\drivers\mrxnet.sys - detected as RTKT_STUXNET.A
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxClsImagePath = "\??\%System%\Drivers\mrxcls.sys"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNetImagePath = "\??\%System%\Drivers\mrxnet.sys"
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.