W32.Nekat.A
W32.Nekat.A is a worm that propagates through removable storage devices and is known to reduce security settings by disabling antivirus and firewall on the hijacked machine. In order to hide its malicious actions W32.Nekat.A creates registry entries that hide or disables many functions of the Control Panel, Windows Registry Editor, Task Manager and the command shell.
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\XCryptOR\W32Roty.A\hAka1 = gSysTray.comhHKEY_LOCAL_MACHINE\Software\XCryptOR\W32Roty.A\hAka2 = gscvhost.exehHKEY_LOCAL_MACHINE\Software\XCryptOR\W32Roty.A\hAka4 = gtest.comhHKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USER\Control Panel\donft load\haccess.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\happwiz.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hhdwwiz.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hinetcpl.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hintl.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hjoy.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hmain.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hncpa.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hnetcpl.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\hnusrmgr.cplh = gNohHKEY_CURRENT_USER\Control Panel\donft load\htimedate.cplh = gNohHKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\ParametersHKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanserver\Shares\FirewallPolicy\StandardProfile\AuthorizedApplications\List\h%Windir%\SysTray.comh = g%WINDIR%\SysTray.com:*:Enabled:SysTrayh\hShellh = g%Windir%\SysTray.comh\hTest_Amorh = gCSCFlags=0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.