Home Malware Programs Worms W32.Pholdicon

W32.Pholdicon

Posted: September 19, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 55
First Seen: September 19, 2013
OS(es) Affected: Windows

W32.Pholdicon is a worm that downloads potentially malicious files and circulates through network shares and removable media. W32.Pholdicon seems to be a Windows folder icon and is distributed through removable media and network shares. When executed, W32.Pholdicon creates the potentially malicious files. W32.Pholdicon creates the registry entry so that it can run automatically every time Windows is started. W32.Pholdicon downloads and runs potentially malicious files from the certain remote location.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



[DRIVE LETTER]\Photo\Photo.exe File name: [DRIVE LETTER]\Photo\Photo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[DRIVE LETTER]\Photo.exe File name: [DRIVE LETTER]\Photo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[MAPPED NETWORK DRIVE]\Photo.exe File name: [MAPPED NETWORK DRIVE]\Photo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[REMOVABLE DRIVE]\Photo.exe File name: [REMOVABLE DRIVE]\Photo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Photo" = "[DRIVE LETTER]\Photo\Photo.exe"
Loading...