Home Malware Programs Worms Wintoo

Wintoo

Posted: March 28, 2006

Wintoo, also known as Sexer, is an Internet worm that propagates by e-mail in messages with infected executable attachments. The message's body and subject are written in Russian.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 kavutil.bmp
    2 kavutil.exe
    3 sex.bmp
    4 sex.exe
    5 win2drv.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKAVutilHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunWin2Drv

Related Posts

Loading...