Home Malware Programs Trojans Worm.Win32.WBNA.aot

Worm.Win32.WBNA.aot

Posted: August 23, 2011

Worm.Win32.WBNA.aot is a self-replicating worm that can infect computer systems without users' knowledge. Worm.Win32.WBNA.aot makes your PC vulnerable to further attacks and downloads and install other malware threats that could harm your data. Once Worm.Win32.WBNA.aot installs on your machine, it may notably worsen your PC's performance. Worm.Win32.WBNA.aot can disable security applications, change system settings and collect personal information to forward it to a remote attacker. You should depend on a legitimate anti-malware program to eliminate Worm.Win32.WBNA.aot from your computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\5ykq.log File name: %AppData%\5ykq.log
Mime Type: unknown/log
%AppData%\cnqsm.exe File name: %AppData%\cnqsm.exe
File type: Executable File
Mime Type: unknown/exe
%AppData%\manager.exe File name: %AppData%\manager.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWSAPAGENT\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWSAPAGENTHKEY_LOCAL_MACHINE\SOFTWARE\tgs90gv74rHKEY_LOCAL_MACHINE\SOFTWARE\skd3uf1wbdHKEY_LOCAL_MACHINE\SOFTWARE\f6h45yhjqaHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store DatabaseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\cnqsm\DEBUGHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\cnqsm HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Local Account Authority Service\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Local Account Authority ServiceHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWSAPAGENT\0000\Contro
Loading...