Home Malware Programs Worms W32.Griptolo

W32.Griptolo

Posted: March 30, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 7
First Seen: March 30, 2012
OS(es) Affected: Windows

W32.Griptolo is a computer worm that circulates through removable drives. W32.Griptolo also downloads potentially malevolent files onto the corrupted PC. When executed, W32.Griptolo replicates itself by creating the certain files on all removable drives and runs when the drives are accessed. W32.Griptolo then creates the certain registry entry so that it can launch every time you boot up Windows. W32.Griptolo also creates the particular registry entry in order to evade the Windows firewall. W32.Griptolo tries to access the specific websites. W32.Griptolo also tries to download and run possibly infectious files onto the affected computer system. Select a genuine security program to eliminate W32.Griptolo from the infected computer as early as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles%\Java\jre-10\bin\UF File name: %ProgramFiles%\Java\jre-10\bin\UF
Group: Malware file
%SystemDrive%\Folder[ONE SPACE].exe File name: %SystemDrive%\Folder[ONE SPACE].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\Java\jre-10\bin\jusched.exe File name: %ProgramFiles%\Java\jre-10\bin\jusched.exe
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\autorun.inf File name: %DriveLetter%\autorun.inf
Mime Type: unknown/inf
Group: Malware file
%DriveLetter%\folder[ONE SPACE].exe File name: %DriveLetter%\folder[ONE SPACE].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%ProgramFiles%\Java\jre-10\bin\jusched.exe" = "%ProgramFiles%\Java\jre-10\bin\jusched.exe:*:Enabled:JavaUpdate10"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"SunJavaUpdateSched10" = "%ProgramFiles%\Java\jre-10\bin\jusched.exe"
Loading...