Home Malware Programs Worms W32.Wergimog.B

W32.Wergimog.B

Posted: May 18, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 63
First Seen: May 18, 2012
Last Seen: June 6, 2022
OS(es) Affected: Windows

W32.Wergimog.B is a worm that tries to circulate by copying itself to removable drives. W32.Wergimog.B may also create a certain file in order to run whenever the drive is used on another PC. W32.Wergimog.B also opens a back door and may steal data from the infected computer. W32.Wergimog.B may modify the Windows Registry by creating registry entries, so that it can load every time you start Windows. W32.Wergimog.B creates the mutexes 'skkd)*u32hqiajnzja' and '(asdj2j3e)*oqwjkz' so that only one instance of the copy runs on the affected machine. W32.Wergimog.B runs the Explorer.exe process and inserts its code into it. W32.Wergimog.B may also insert itself into other processes as well. W32.Wergimog.B also tries to steal the information on the corrupted PC such as usernames, user account types, OS versions and FileZilla account details. W32.Wergimog.B also modifies any posts made on the social networking websites such as Facebook, Twitter, Myspace, Hyves, Omegle, Linkedin and Hi5. W32.Wergimog.B searches for other malware threats on the affected computer and ends any malware processes it detects.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%/Application Data/Microsoft/services[THREE RANDOM NUMBERS].exe File name: %UserProfile%/Application Data/Microsoft/services[THREE RANDOM NUMBERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\autorun.inf File name: %DriveLetter%\autorun.inf
Mime Type: unknown/inf
Group: Malware file
%DriveLetter%\adober~1/dsci5829.jpg File name: %DriveLetter%\adober~1/dsci5829.jpg
Mime Type: unknown/jpg
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Adobe Reader Speed Launcher" = "%UserProfile%/Application Data/Microsoft/services[THREE RANDOM NUMBERS].exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Adobe Reader Speed Launcher" = "%UserProfile%/Application Data/Microsoft/services[THREE RANDOM NUMBERS].exe"

Additional Information

The following URL's were detected:
initiateintenselyadvancedthefile.vip
Loading...