Home Malware Programs Worms W32.Greypac

W32.Greypac

Posted: October 3, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 26
First Seen: October 3, 2012
OS(es) Affected: Windows

W32.Greypac is a worm that replicates itself to shared web folders. W32.Greypac may be distributed to the targeted computer as a malicious email attachment. Once executed, W32.Greypac replicates itself to the certain location of the corrupted machine. W32.Greypac creates the specific registry entry, which allows it to run automatically every time you start Windows. W32.Greypac then downloads the certain image file and illustrates it. W32.Greypac may also create and show a window with the title 'Main_Window'. W32.Greypac enumerates all system drivers from C through Z. W32.Greypac searches fixed drives for files with the '.htm' and '.php' file extensions.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Settings\search.cmd File name: C:\Settings\search.cmd
Mime Type: unknown/cmd
Group: Malware file
%UserProfile%\Application Data\rcs.jpg File name: %UserProfile%\Application Data\rcs.jpg
Mime Type: unknown/jpg
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Search" = "C:\Settings\search.cmd"

Additional Information

The following URL's were detected:
martixstar.net
Loading...