Home Malware Programs Viruses Virus:Win32/Drowor.B

Virus:Win32/Drowor.B

Posted: February 15, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 23
First Seen: February 15, 2013
Last Seen: July 2, 2020
OS(es) Affected: Windows

Virus:Win32/Drowor.B is a virus that affects portable executable (PE) files, such as EXE, DLL, SCR and SYS files on the affected computer including removable drives. Virus:Win32/Drowor.B ends security processes usually related to security programs from running and overwrites some of their code, which means that a PC user may have to reinstall infected security programs. When installed, Virus:Win32/Drowor.B makes system changes by dropping potentially malicious files from remote servers and making registry modifications. The files dropped by Virus:Win32/Drowor.B may be other malware threats, or updated versions of a virus. Virus:Win32/Drowor.B then overwrites part of the malicious file. Virus:Win32/Drowor.B will make security programs on the compromised PC to run not properly. Virus:Win32/Drowor.B adds a copy of itself as 'services.exe'. Virus:Win32/Drowor.B creates the registry entry to assure it runs automatically every time you start Windows.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\Microsoft\Windows\Cookies\cf File name: %AppData%\Microsoft\Windows\Cookies\cf
Group: Malware file
%AppData%\Microsoft\Windows\Cookies\rua File name: %AppData%\Microsoft\Windows\Cookies\rua
Group: Malware file
%AppData%\Microsoft\Windows\Cookies\ru File name: %AppData%\Microsoft\Windows\Cookies\ru
Group: Malware file
[system folder]\[random hex number]\services.exe File name: [system folder]\[random hex number]\services.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "services" = "[system folder]\[random hex number]\services.exe"
Loading...