Win32/Conficker.X is a worm that repeatedly tries to connect to various web pages. It tries to download several files from the addresses. It can be controlled remotely.
Installation
When executed, the worm copies itself in some of the the following locations:
%system%\%variable%.dll
%program files%\Internet Explorer\%variable%.dll
%program files%\Movie Maker\%variable%.dll
%program files%\Windows NT\%variable%.dll
%appdata%\%variable%.dll
%temp%\%variable%.dll
A string with variable content is used instead of %variable% .
The worm loads and injects the %variable%.dll library into the following processes:
explorer.exe
services.exe
svchost.exe
The worm registers itself as a system service with the name combined from the following strings: