VIRUS-W32/Stemclover Worm
in
W32/Stemclover is a worm. The worm will infect Windows systems and spreads through removable drives and Network drives.
The worm will arrive as a dropped file from the shared folder or mapped drive or removable drive.
Upon execution, the worm copies itself as aniee.com and hanny.exe in the System folder.
The worm modifies registry at the following location to load itself during each startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
It also copies winsys.exe, autorun.inf and Dokter Cinta.Jpg.exe in the removable drives.
The worm is capable of disabling some security related applications.
This worm first appeared on October 09, 2007.
- pankaj's blog
- Add new comment
- 339 reads
- Email this page