W32/Autorun-ANF

Category: Viruses and Spyware Protection available since:30 Jul 2009 13:43:35 (GMT)
Type: Win32 worm Last Updated:30 Jul 2009 13:43:35 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Autorun-ANF is a worm for the Windows platform.

When run W32/Autorun-ANF creates the following files:

<System>\28463\svchost.001
<System>\28463\svchost.exe
<System>\regsvr.exe
<System>\setup.ini
<Windows>\regsvr.exe
<System>\svchost .exe

The file svchost.exe is detected as Ardamax and is a keylogger.

W32/Autorun-ANF also spreads via removable shared drives by copying itself to the removable drive as
<Root>\regsvr.exe
<Root>\New Folder.exe

and creating the file
<Root>\autorun.inf

The file <Root>\autorun.inf is designed to run the worm when the removable drive in connected to an uninfected computer.

The following registry entry is created to run regsvr.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Msn Messsenger
<System>\regsvr.exe

The following registry entry is changed to run regsvr.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe regsvr.exe

The following registry entry is set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
0x00000001

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
GlobalUserOffline
0x00000000


download Try Sophos products for free
Download now