Home Malware Programs Worms WORM_STUXNET.A

WORM_STUXNET.A

Posted: July 21, 2010

WORM_STUXNET.A is a computer worm that spreads on removable USB drives. WORM_STUXNET.A does this by creating an Autorun.Inf file on the root of each drive inserted to the compromised machine. WORM_STUXNET.A will run automatically if the affected drive is accessed, causing the targeted system endless problems.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\drivers\mrxcls.sys - detected as RTKT_STUXNET.A
    2 %System%\drivers\mrxnet.sys - detected as RTKT_STUXNET.A

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxClsImagePath = "\??\%System%\Drivers\mrxcls.sys"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNetImagePath = "\??\%System%\Drivers\mrxnet.sys"
Loading...