Upon first execution W32/Warezov.AKD drops the files w32tcomr.dll and w32tcomr.exe into the %SYSDIR%. The dropped files are all detected as W32/Warezov.AKD also.
Note: %SYSDIR% refers to the System directory. The default path for the respective operating systems is as follows:
- Windows 95/98/Me - C:\Windows\System
- Windows NT/2000 - C:\Winnt\System32
- Windows XP - C:\Windows\System32
Creates the registry key:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\w32tcomr]
and adds several values to it to make the file w32tcomr.dll run at startup.
On next reboot w32tcomr.dll drops more files, all detected as W32/Warezov.AKD as well.
|