Home Malware Programs Worms Cacfu.A

Cacfu.A

Posted: January 10, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 35
First Seen: January 10, 2011
Last Seen: January 22, 2022
OS(es) Affected: Windows

Worm.Cacfu.A (Cacfu.A) is a worm, which can penetrate into vulnerable Windows PCs. Worm.Cacfu.A can copy itself to numerous removable drives, which might enable it to spread to other computers. Worm.Cacfu.A drops malicious files on the compromised machine. Worm.Cacfu.A can slow PC performance or block access to some Windows components. Worm.Cacfu.A controls the targeted Windows system with two infected executable files. Worm.Cacfu.A can add, delete and compromise processes, change Windows File Protection, so that malicious processes are not found. Worm.Cacfu.A can also record its victim's browsing activities. Worm.Cacfu.A can record your keyboard inputs, disable Safe Mode and Windows Security Center features, delete administrative rights to Windows programs, such as Registry Editor and Task Manager. Worm.Cacfu.A hides itself to avoid detection and removal by security tools.

Aliases

Worm/VB.FPZ [AVG]Trojan.VB-281 [ClamAV]Win32:VB-BBA [Trj] [Avast]Trj/VB.RG [Panda]Win32.Worm.VB.DG [BitDefender]W32/Generic.d [McAfee]Trj/CI.A [Panda]Worm/AutoRun.IG [AVG]Email-Worm.Win32.Brontok.ab [Ikarus]Trojan.Win32.AutoIT.gen (v) [Sunbelt]Email-Worm.Win32.Brontok.ab!IK [a-squared]Win32/ASuspect.HDAEB [eTrust-Vet]Mal/Sohana-A [Sophos]Trojan.DownLoad1.53716 [DrWeb]Gen:Trojan.Heur.tqLfrrdAGikib [BitDefender]
More aliases (70)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\WINDOWS\svchost.exe File name: svchost.exe
Size: 45.05 KB (45056 bytes)
MD5: b600691ea07a447c0b1ce34f941e2d74
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\svchost.exe
Group: Malware file
Last Updated: December 6, 2020
SocksA.exe File name: SocksA.exe
Size: 45.05 KB (45056 bytes)
MD5: 75c6e5acd9328b24724df8ae554a33b7
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 19, 2011
%WINDIR%\missAU.exe File name: missAU.exe
Size: 324.37 KB (324373 bytes)
MD5: c7463781eba7f02ba2ac1f42b549891e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: January 12, 2011
%WINDIR%\system32\SocksA.exe File name: SocksA.exe
Size: 45.05 KB (45056 bytes)
MD5: 9d7fa0d3357967a9aac7c427a27fd5f0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 11, 2011
H:\System Volume Information\_restore{3B8FC840-B9D8-4860-B4A8-F002A2ACEF1F}\RP44\A0018147.exe File name: A0018147.exe
Size: 45.05 KB (45056 bytes)
MD5: 38f0d47e4bbf2c5f05c51f6c48a90629
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: H:\System Volume Information\_restore{3B8FC840-B9D8-4860-B4A8-F002A2ACEF1F}\RP44\A0018147.exe
Group: Malware file
Last Updated: January 22, 2022
Loading...