W32.Formshared.A
Aliases: N/A
Variants: N/A
Classification: Malware
Category: Computer Worm
Status: Inactive
Spreading: Slow
Geographical info: Some parts of Asia, Europe, North and South America, Africa and Australia
Removal: Easy
Platform: W32
Discovered: 02 Jan 2007
Damage: Low
Characteristics: On January 2, 2007, a worm that tries to spread by creating a copy of Infostealer via file-sharing applications was discovered. This worm is W32.Formshared.A. The infostealer that is copied by this worm is a generic detection for Trojan horse programs usually tries to steal important information. This worm primarily infects Windows systems.
W32.Formshared.A Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Formshared.A from your computer.
More details about W32.Formshared.A
This worm performs several actions in propagating. First, it copies itself to %Windir%\checkers5.exe and adds a value to the system registry subkey. Then, the worm creates a folder which is %Windir%\Shared. It also creates a number of files with the .zip extension. These files contain an Infostealer. This means that sensitive information can be stolen such as the password and bank account details. After randomly selecting a name for the .zip file, the worm registers its file-sharing application to several servers. Hence, propagation of the worm is successfully installed.The W32.Formshared.A software uses an idle system port. It opens this to connect to the Internet. The backdoor is used to connect to a remote server. The program will then wait for commands. These are commonly executed in the computer without the user’s consent. Files and programs in the infected system may be changed unexpectedly. The webcam or CD drive can be opened and closed. The user’s activities can be recorded using a keylogger function. Gathered data can be sent to a remote server.
Browse for more malware information
- W32.Formshared.A
- W32.Fourseman.A
- W32.Fractalove.A@mm
- W32.Fragl
- W32.Francette.Worm
- W32.Fregit@mm
- W32.Frethem.Gen@mm
- W32.Friendgreet.worm
- W32.Fruit.Mirc
- W32.Fubalca
- W32.Fujacks!gen
- W32.Funner
- W32.Funsoul@mm
- W32.Gabloliz.A
- W32.Gammima
- W32.Gammiy
- W32.Ganbate.A
- W32.Gangbot
- W32.Gase.intd
- W32.Gaut.A
- W32.Gavgent.A
- W32.Gaze@mm
- W32.Gillich.Mirc
- W32.Girls.Irc
- W32.Gluber.B@mm
- W32.Glupzy.A
- W32.Gnuman.Worm
- W32.Gobot.A
- W32.Gokar.A@mm
- W32.Goner.A@mm