Home Malware Programs Worms Worm.Win32.AutoRun.bhtv

Worm.Win32.AutoRun.bhtv

Posted: May 2, 2011

Worm.Win32.AutoRun.bhtv is a malicious computer worm that obtains access to the affected computer in the background without your awareness and permission. Worm.Win32.AutoRun.bhtv will download infected files to the computer without a victim's consent which will result in security threat. Worm.Win32.AutoRun.bhtv circulates and copies itself stealthily on your computer through available resources. Worm.Win32.AutoRun.bhtv also uses secret technology to steal and send the data that involve games, such as Talesweaver, ROHAN, Maple Story, etc. to a remote sever. Worm.Win32.AutoRun.bhtv is a dangerous threat to any computer system and should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\%UserName%1\random
    2 %UserProfile%\%UserName%1\winlogon

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]=random.exeHKEY..\..\..\..{RegistryKeys}NVIDIA Media Center Library = "%NVIDIA Media Center Library = "%UserProfile%\%UserName%1\winlogon.exe"UserProfile%\%UserName%1\winlogon.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...