Home Malware Programs Worms Worm.Folstart.A


Posted: May 31, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 595
First Seen: May 31, 2011
Last Seen: May 25, 2022
OS(es) Affected: Windows

Worm.Folstart.A is a worm that spreads from one computer to another via removable media. Although Worm.Folstart.A does not infect the system files directly, it can modify a variety of system settings based on the attacker's wishes. Worm.Folstart.A enters the targeted computer system without a PC user's permission and knowledge. Once executed, Worm.Folstart.A drops malicious processes. The main way for Worm.Folstart.A to proliferate is to exploit removable storage strives. Worm.Folstart.A queries a certain registry entry to check if there are any USB devices connected to the PC. Once a device is detected, Worm.Folstart.A searches the drive for any folders that might be there and replicates itself into the folder, using the folder’s name, without any extension. Worm.Folstart.A even copies the icon of the folder, so when a PC user opens the device and sees the icon, Worm.Folstart.A is executed as a simple folder.


Worm.Generic.311224 [BitDefender]Worm.Generic.320405 [BitDefender]Worm/Generic_r.JV [AVG]W32/Rotinom.SME!tr [Fortinet]W32/AutoRun.AL.gen!Eldorado [F-Prot]Worm/Folstart.A.19 [AntiVir]W32/Agent2.LDT!tr [Fortinet]Worm/Folstart.A.21 [AntiVir]P2P-Worm.Win32.Palevo.erme [Kaspersky]W32/Dx.SWB!tr [Fortinet]Trojan.Win32.Agent [Ikarus]Worm/Folstart.A.20 [AntiVir]Trojan-Dropper.Win32.Autoit.bgd [Kaspersky]W32/MalwareF.CGLQ [F-Prot]Worm.Folstart.A2 [CAT-QuickHeal]
More aliases (97)