Home Malware Programs Worms WORM/Nyxem.BK.worm

WORM/Nyxem.BK.worm

Posted: October 13, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 143
First Seen: October 13, 2011
Last Seen: December 23, 2020
OS(es) Affected: Windows

WORM/Nyxem.BK.worm is a malignant network-aware worm which invades the targeted computer system stealthily without a PC user's permission and knowledge. WORM/Nyxem.BK.worm uses available network resources to spread and replicate itself further. WORM/Nyxem.BK.worm may display annoying pop-up ads, slow down your PC and cause unwanted system crashes. WORM/Nyxem.BK.worm connects to a remote server so that it can track your browsing habits and transmit them to attackers. WORM/Nyxem.BK.worm can also reset your account settings, change your default homepage and redirect you to unwanted malicious websites. Uninstall WORM/Nyxem.BK.worm immediately upon detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Local Settings\Temp\kjkkklklj.bat setupapp7070010000.exe File name: %UserProfile%\Local Settings\Temp\kjkkklklj.bat setupapp7070010000.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'Protection Center'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations 'LowRiskFileTypes' = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings 'ProxyServer' = 'http=127.0.0.1:5555'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download 'RunInvalidSignatures' ='1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce 'SelfdelNT'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'Protection Center'vHKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
Loading...