Home Malware Programs Worms W32.Inabot

W32.Inabot

Posted: April 24, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 119
First Seen: April 24, 2013
Last Seen: July 3, 2023
OS(es) Affected: Windows

W32.Inabot is a worm that circulates through removable drives and network shares. W32.Inabot steals information from the infected computer. When W32.Inabot is executed, it creates the potentially malicious file. Once run, the original executable file is deleted in order to disguise its existence on the affected computer. W32.Inabot then creates the registry entry so that it runs every time Windows is started. W32.Inabot then connects to one of the command-and-control (C&C) servers and opens a back door on the corrupted PC. W32.Inabot grabs information from the victimized PC and transfers it to the remote attacker. W32.Inabot can also launch distributed-denial-of-service (DDoS) attacks through UDP or TCP flooding.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\[RANDOM CHARACTERS FILE NAME].exe File name: %UserProfile%\Application Data\[RANDOM CHARACTERS FILE NAME].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM KEY]" = "%UserProfile%\Application Data\[RANDOM CHARACTERS FILE NAME].exe"
Loading...