W32/Autorun-ANF is a worm for the Windows platform.
When run W32/Autorun-ANF creates the following files:
<System>\28463\svchost.001
<System>\28463\svchost.exe
<System>\regsvr.exe
<System>\setup.ini
<Windows>\regsvr.exe
<System>\svchost .exe
The file svchost.exe is detected as Ardamax and is a keylogger.
W32/Autorun-ANF also spreads via removable shared drives by copying itself to the removable drive as
<Root>\regsvr.exe
<Root>\New Folder.exe
and creating the file
<Root>\autorun.inf
The file <Root>\autorun.inf is designed to run the worm when the removable drive in connected to an uninfected computer.
The following registry entry is created to run regsvr.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Msn Messsenger
<System>\regsvr.exe
The following registry entry is changed to run regsvr.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe regsvr.exe
The following registry entry is set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
0x00000001
Registry entries are set as follows:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
GlobalUserOffline
0x00000000