W32/Hagbard-A may copy itself to any of the following locations under various filenames:Ĭ:\Program Files\Files\Kazaa Lite\My Shared Folder\Ĭ:\Program Files\Morpheus\My Shared Folder\Ĭ:\Program Files\Warez P2P Client\My Shared Folder\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run The worm creates the following registry entry in order to run itself on startup: HKCU\Software\Microsoft\Internet Explorer\Main The worm may change the Start Page in Internet Explorer by changing the following registry entry: The worm may change the Start Page in Internet Explorer. The link points to a copy of the worm stored on the infected system. W32/Hagbard-A may send messages to other users of Windows Messenger, containing a link and the following text: The installed file is also detected as W32/Hagbard-A. The worm also installs a web server, allowing a remote user access to files on the infected system. W32/Hagbard-A copies itself to a number of locations on the hard drive, including shared folders for various peer-to-peer applications. W32/Hagbard-A is a worm that attempts to spread through peer-to-peer and chat program networks.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |