SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  AutoRun.WUU
AutoRun.WUU is a Worm. Worms spread from computer to computer, making copies of themselves over the network. They could spread over email, IM, peer-to-peer networks, or directly over the wire by leveraging vulnerabilities. AutoRun.WUU is compressed using the executable packer and its file size is 101,088 bytes. This malware is written in Borland Delphi.

AutoRun.WUU drops the following files on the hard drive:

  • C:\WINDOWS\system32\drivers\TXPlatform.exe (101088 bytes)
  • C:\z.tmp (3328 bytes)
  • C:\z1.tmp (3328 bytes)
It also changes Windows registry:
  • Creates key "HKLM\System\CurrentControlSet\Services\RESSDT".
  • Creates value "ImagePath"="c:\z1.tmp" in key "HKLM\System\CurrentControlSet\Services\RESSDT".
  • Creates value "DisplayName"="RESSDT" in key "HKLM\System\CurrentControlSet\Services\RESSDT".
AutoRun.WUU configures following services on NT based machines:
  • Creates service "RESSDT (RESSDT)" as "c:\z1.tmp".
It also monitors the list of running processes.


Relevant Information