W32/Ackantta.F Worm
| Name |
W32/Ackantta.F Worm |
| Aliases |
W32.Ackantta.F@mm |
| Updated on |
July 3, 2009 |
Virus Information - W32/Ackantta.F Worm:
W32/Ackantta.F is an email worm. The worm will infect Windows systems and spreads through email.
The from address of the infected email will be:
Sarah@michaeljackson.com
The subject of the infected email will be:
Remembering Michael Jackson
The infected email will contain the attachment:
Michael songs and pictures.zip
The .zip attachment will contain:
MichaelJacksonsongsandpictures.doc.exe
The body of the infected email is:

Upon execution, the worm drops the following files in Windows\System32 folder:
jushed.exe
java2.exe
jvm.exe
SKYNET[RANDOM LETTERS].dll
It drops SKYNE[RANDOM LETTERS].sys in Windows\System32\drivers folder.
It drops the following non malware files:
java.ini in Windows folder
SKYNET[RANDOM LETTERS].dat and SKYNETlog.dat in Windows\System32 folder
The worm modifies registry at the following locations:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

|