Home Malware Programs Viruses W32.Fypzserv

W32.Fypzserv

Posted: July 18, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 148
First Seen: July 18, 2013
Last Seen: June 13, 2023
OS(es) Affected: Windows

W32.Fypzserv is a virus that takes over specific documents, archives, and media files on the infected computer system. W32.Fypzserv may be proliferate through removable drives. When W32.Fypzserv is executed, it replicates itself as the potentially malicious files. W32.Fypzserv creates the potentially malicious files on all removable drives. W32.Fypzserv creates the registry entry so that it can run automatically every time Windows is started. W32.Fypzserv creates the registry entry to lower security settings on the corrupted PC. W32.Fypzserv creates the registry entries to disable certain applications on the affected computer. W32.Fypzserv modifies all files with the extensions including docx, doc, xls, xlsx, pptx, ppt, mdb, mdf, accdb, jpg, jpeg, zip, rar, pdf, pst, psd, cdr, avi, mkv, mp4, mov, vob, mp3, iso, nrg, flv and swf. Once the files are compromised by W32.Fypzserv, they will not work until they have been repaired. W32.Fypzserv modifies the registry entries to disguise its existence and to change Internet Explorer settings. W32.Fypzserv also modifies other registry entries.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%DriveLetter%\Image.exe File name: %DriveLetter%\Image.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Movie.exe File name: %DriveLetter%\Movie.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\[CURRENT USER].exe File name: %DriveLetter%\[CURRENT USER].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%SystemDrive%\[CURRENT USER].exe File name: %SystemDrive%\[CURRENT USER].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\igfxhost.exe File name: %UserProfile%\igfxhost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"igfxhost" = "%UserProfile%\igfxhost.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskMgr" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableRegistryTools" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\"LastIndex" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"DisableTaskMgr" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"DisableRegistryTools" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\"CheckedValue" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt\"UncheckedValue" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\"UncheckedValue" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\"CleanShutdown" = "0"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\"Start" = "4"

Additional Information

The following URL's were detected:
removember.website
Loading...