Worm.Win32.Fujack

Detect Date 05/21/2007
Class Worm
Platform Win32
Description

This worm spreads on the hard disk of the victim machine and to write-accessible network resources. It is a Windows PE EXE file. Modifications of this program may vary in size from 26KB to 129KB. The program may be packed with a range of packers.

Installation

When launched, the worm copies its executable file as follows:

%System%driversspoclsv.exe

In order to ensure that the worm is launched automatically when the system is rebooted, it registers its executable file in the system registry:

[HKCUSoftwareMicrosoftWindowsCurrentVersionRun]



"Svcshare" = "%System%driversspoclsv.exe"







[HKLMSoftwareMicrosoftWindowsCurrentVersionRun]



"Svcshare" = "%System%driversspoclsv.exe"