Home Malware Programs Worms Worm.Emudbot.A

Worm.Emudbot.A

Posted: May 21, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 152
First Seen: August 15, 2011
Last Seen: August 5, 2020
OS(es) Affected: Windows

Worm.Emudbot.A is a worm that circulates to other PCs via the network. Worm.Emudbot.A replicates itself and uses removable drives to affect targeted computers. After successful installation on the compromised machine, Worm.Emudbot.A makes certain changes on the infected PC system; it drops malicious files. Worm.Emudbot.A disguises itself, and thus, is difficult to detect and remove it from the corrupted PC. Worm.Emudbot.A connects to the Internet, modifies Internet Explorer, and attempts to drop additional malicious files to the computer. Worm.Emudbot.A can also use Windows Live Messenger for sending messages to the contacts of a PC user to infect other PCs. Uninstall Worm.Emudbot.A to protect your computer from harm.

Aliases

Generic Worm [Panda]Cryptic.DXX [AVG]W32/Kryptik.DELF!tr [Fortinet]Backdoor/Win32.Emud.gen [Antiy-AVL]W32/Autorun-BSJ [Sophos]Generic BackDoor!1mn [McAfee-GW-Edition]TR/Kazy.sjs [AntiVir]TrojWare.Win32.Agent.kzj [Comodo]Gen:Variant.Delf.23 [BitDefender]Backdoor.Win32.Emud.izj [Kaspersky]Win32.TRKazy.Sjs [eSafe]EmailWorm [K7AntiVirus]Generic BackDoor.abh [McAfee]Worm.Emudbot.A [CAT-QuickHeal]SHeur2.AFZB [AVG]
More aliases (169)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\MPK\MPK.exe File name: MPK.exe
Size: 1.32 MB (1327264 bytes)
MD5: dab075811a93350f4e61c74a8c907f9f
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MPK
Group: Malware file
Last Updated: May 28, 2012
file.exe File name: file.exe
Size: 267.26 KB (267264 bytes)
MD5: fc2ad4b7b5aea3e77b6f76aeba333cdd
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 28, 2012
sik.exe File name: sik.exe
Size: 278.01 KB (278016 bytes)
MD5: c974f01108183491236281fbb6f30d81
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 28, 2012
wui.exe File name: wui.exe
Size: 251.9 KB (251904 bytes)
MD5: 5c87f0f986d962283ea3452eae4543fa
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 28, 2012
%TEMP%\wui.exe File name: wui.exe
Size: 102.4 KB (102400 bytes)
MD5: 709579d3df6cab612970a8b6dfbbaf9f
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: August 26, 2011
%WINDIR%\system32\sysv\svchost.exe File name: svchost.exe
Size: 969.21 KB (969216 bytes)
MD5: 946e8e431b5716196fa9b4e1fe86bc61
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\sysv
Group: Malware file
Last Updated: June 19, 2012
%WINDIR%\Silent Hill 3 screensaver.scr File name: Silent Hill 3 screensaver.scr
Size: 1.3 MB (1300434 bytes)
MD5: 613ccfcd0506721deb307dfde9b5899e
Detection count: 35
Mime Type: unknown/scr
Path: %WINDIR%
Group: Malware file
Last Updated: May 28, 2012
%TEMP%\sik.exe File name: sik.exe
Size: 141.31 KB (141312 bytes)
MD5: e56d4b922f24442563b908d7d2fba103
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: August 15, 2011
%WINDIR%\system32\drivers\system64y.sys File name: system64y.sys
Size: 6.52 KB (6528 bytes)
MD5: a06b64d1a272b354933c03a502c64fb9
Detection count: 7
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: May 28, 2012
%WINDIR%\system32\audiohd.exe File name: audiohd.exe
Size: 156.47 KB (156474 bytes)
MD5: 7d2e6715993b58a2792f7669795b8c31
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 28, 2012
%WINDIR%\TEMP\jygip.exe File name: jygip.exe
Size: 328.7 KB (328704 bytes)
MD5: 60b8a2f4dd06f67acb566dc34a4ee2d8
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP
Group: Malware file
Last Updated: April 17, 2013
Loading...