1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Worm:W32/Kaxela.A

Name : Worm:W32/Kaxela.A
Detection Names : Worm:W32/Kaxela.A
Backdoor.Win32.Agent.msv
Aliases : Worm:Win32/Winko.A (Microsoft)
TROJ_NSPM.JR (Trend Micro)
W32/Winko.worm.gen (McAfee)
Packed.Generic.115 (Symantec)
Size:18067
Category:Malware
Type:Worm
Platform:W32

Summary

A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network.

Details


File System Changes
Creates these files:

  • %System%\[Random].DLL
  • %System%\[Random].EXE
  •  C:\autorun.inf
  • C:\auto.exe
  • %System%\delme.bat



Process Changes
Uses these temporary processes:

  • %System%\[Random].EXE


These modules were loaded into other processes:

  • %System%\[Random].DLL


Writes in memory of these processes:

  • %System%\services.exe
  • %System%\lsass.exe
  • %System%\svchost.exe



Network Connections
Attempts to download files from:

  • http://alexa.verynx.cn//[...]xa.txt


Attempts to connect to:

  • http://211.100.21.4/[..].cnt



Registry Modifications
Sets these values:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[random] = "%System%\[random].EXE -k"


Creates these keys:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[random]
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_[random]


Deletes these keys:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc


Additional Details

Kaxela is a type of autorun worm that propogates through infected disks and removable drives. This means that a user must physically connect the disk or drive to their system to become infected.

The worm infects the system by dropping a copy of itself and the autorun.inf file into the drive. During the infection process, the worm will make copies of itself and place them in various, randomly generated files, then delete the original copy of the worm.

Once installed, the worm will also attempt to connect to two sites, most likely in order to send information, to download malicious programs or to receive further commands.