Home Malware Programs Worms Win32/Conficker.AA

Win32/Conficker.AA

Posted: January 12, 2009

Win32/Conficker.AA, also known as W32/Worm.AHGV, Win32.Worm.Downadup, Net-Worm.Win32.Kido.bg, Worm:Win32/Conficker, W32/Conficker.worm.gen, and Mal/Conficker, is a malicious worm that spreads to computers in a local network by utilizing Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability. The Win32/Conficker.AA worm can perform numerous hideous actions on your PC. Win32/Conficker.AA worm can block your access to security websites as well as erase System Restore points before infecting your computer. Win32/Conficker.AA will remove all NTFS file permissions, with the exception of execute and directory traversal files in order to shield itself from being deleted.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\[Random Name].dll
    2 %Program Files%\Internet Explorer\[Random Name].dll
    3 %Program Files%\Movie Maker\[Random Name].dll
    4 %System32%\[Random Name].dll
    5 %Temp%\[Random Name].dll
Loading...