Home / malwarePDF  

Worm:Win32/Cosmu.C


First posted on 29 October 2013.
Source: Microsoft

Aliases :

There are no other names known for Worm:Win32/Cosmu.C.

Explanation :

Threat behavior

Installation

When it runs, Worm:Win32/Cosmu.C copies itself to <system folder>\cab32.ocx. The malware creates the following files on your PC:

  • <system folder> \cab32.dll - detected as Worm:VBS/Cosmu.C
  • c:\documents and settings\administrator\desktop\facebook.txt


Spreads via€¦

Removable drives

Worm:Win32/Cosmu.C can create the following files on targeted drives when spreading:

  • <targeted drive>:\pig.pif

It also creates an autorun.inf file in the root folder of the removable drive. The file has instructions to launch the malware automatically when the removable drive is connected to a PC with the Autorun feature turned on.
This is a common way for malware to spread. However, autorun.inf files on their own are not necessarily a sign of infection; they are also used by legitimate programs.
This malware description was produced and published using our automated analysis system's examination of file SHA1 94d2629f92d512be984b31326331981ef2b0de99.Symptoms

System changes

The following could indicate that you have this threat on your PC:

  • The presence of the following files:

    <system folder>\cab32.dll
    <system folder>\cab32.ocx
    c:\documents and settings\administrator\desktop\facebook.txt

Last update 29 October 2013

 

TOP