Home Malware Programs Worms Worm.EternalRocks

Worm.EternalRocks

Posted: May 21, 2017

Threat Metric

Ranking: 17,380
Threat Level: 5/10
Infected PCs: 267
First Seen: May 21, 2017
Last Seen: October 3, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



70ec0e2b6f9ff88b54618a5f7fbd55b383cf62f8e7c3795c25e2f613bfddf45d.exe File name: 70ec0e2b6f9ff88b54618a5f7fbd55b383cf62f8e7c3795c25e2f613bfddf45d.exe
Size: 4.35 MB (4359964 bytes)
MD5: 6fdbee99dc99a63ac6a5809450d55ad5
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
7b8674c8f0f7c0963f2c04c35ae880e87d4c8ed836fc651e8c976197468bd98a.exe File name: 7b8674c8f0f7c0963f2c04c35ae880e87d4c8ed836fc651e8c976197468bd98a.exe
Size: 60.92 KB (60928 bytes)
MD5: 32be774b3464637074299e1f16f4b8ea
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
a77c61e86bc69fdc909560bb7a0fa1dd61ee6c86afceb9ea17462a97e7114ab0.exe File name: a77c61e86bc69fdc909560bb7a0fa1dd61ee6c86afceb9ea17462a97e7114ab0.exe
Size: 5.27 MB (5277184 bytes)
MD5: 198f27f5ab972bfd99e89802e40d6ba7
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%PROGRAMFILES%\Microsoft Updates\taskhost.exe File name: taskhost.exe
Size: 61.44 KB (61440 bytes)
MD5: 5f714b563aafef8574f6825ad9b5a0bf
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microsoft Updates\taskhost.exe
Group: Malware file
Last Updated: June 26, 2020
C:\Program Files\Microsoft Updates\svchost.exe File name: svchost.exe
Size: 303.61 KB (303616 bytes)
MD5: 5c9f450f2488140c21b6a0bd37db6a40
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Microsoft Updates\svchost.exe
Group: Malware file
Last Updated: November 28, 2021
c:\Users\<username>\desktop\new folder\23eeb35780faf868a7b17b8e8da364d71bae0e46c1ababddddddecbdbd2c2c64.exe File name: 23eeb35780faf868a7b17b8e8da364d71bae0e46c1ababddddddecbdbd2c2c64.exe
Size: 20.48 KB (20480 bytes)
MD5: f2a5bea9843cfd088c062685be32154f
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\desktop\new folder
Group: Malware file
Last Updated: August 21, 2018
c:\Users\<username>\desktop\new folder\3b4497c7f8c89bf22c984854ac7603573a53b95ed147e80c0f19e549e2b65693.exe File name: 3b4497c7f8c89bf22c984854ac7603573a53b95ed147e80c0f19e549e2b65693.exe
Size: 5.27 MB (5275648 bytes)
MD5: 53f23e72664dc9efd4251ba1b120d932
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\desktop\new folder
Group: Malware file
Last Updated: August 18, 2020
C:\Windows\UpdateInstaller.exe File name: UpdateInstaller.exe
Size: 339.96 KB (339968 bytes)
MD5: 994bd0b23cce98b86e58218b9032ffab
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\UpdateInstaller.exe
Group: Malware file
Last Updated: November 28, 2021
c:\Users\<username>\desktop\new folder\2094d105ec70aa98866a83b38a22614cff906b2cf0a08970ed59887383ee7b70.exe File name: 2094d105ec70aa98866a83b38a22614cff906b2cf0a08970ed59887383ee7b70.exe
Size: 8.19 KB (8192 bytes)
MD5: 5381aa6cc426f13df69a956984614855
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\desktop\new folder
Group: Malware file
Last Updated: August 21, 2018
48b1024f599c3184a49c0d66c5600385265b9868d0936134185326e2db0ab441.exe File name: 48b1024f599c3184a49c0d66c5600385265b9868d0936134185326e2db0ab441.exe
Size: 4.6 KB (4608 bytes)
MD5: 0e83b186a4d067299df2db817b724eb7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 23, 2018

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%PROGRAMFILES%\Microsoft Updates\svchost.exe%PROGRAMFILES%\Microsoft Updates\taskhost.exe
Loading...