Skip to main content

Worm:W32/Kaxela.A

Classification

Category:

Malware

Type:

Worm

Aliases:

  • Worm:W32/Kaxela.A
  • Backdoor.Win32.Agent.msv
  • Worm:Win32/Winko.A (Microsoft)
  • TROJ_NSPM.JR (Trend Micro)
  • W32/Winko.worm.gen (McAfee)
  • Packed.Generic.115 (Symantec)

Summary

Kaxela is a type of autorun worm that propogates through infected disks and removable drives. This means that a user must physically connect the disk or drive to their system to become infected.

Removal

Technical Details

The worm infects the system by dropping a copy of itself and the autorun.inf file into the drive. During the infection process, the worm will make copies of itself and place them in various, randomly generated files, then delete the original copy of the worm.

Once installed, the worm will also attempt to connect to two sites, most likely in order to send information, to download malicious programs or to receive further commands.

File System Changes

Creates these files:

  • %System%\[Random].DLL
  • %System%\[Random].EXE
  • C:\autorun.inf
  • C:\auto.exe
  • %System%\delme.bat

Process Changes

Uses these temporary processes:

  • %System%\[Random].EXE

These modules were loaded into other processes:

  • %System%\[Random].DLL

Writes in memory of these processes:

  • %System%\services.exe
  • %System%\lsass.exe
  • %System%\svchost.exe

Network Connections

Attempts to download files from:

  • https://alexa.verynx.cn//[...]xa.txt

Attempts to connect to:

  • https://211.100.21.4/[..].cnt

Registry Modifications

Sets these values:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[random] = "%System%\[random].EXE -k"

Creates these keys:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[random]
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_[random]

Deletes these keys:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.