W32/Autorun-BVN

Category: Viruses and Spyware Protection available since:01 Apr 2012 02:01:35 (GMT)
Type: Win32 worm Last Updated:01 Apr 2012 02:01:35 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Autorun-BVN exhibits the following characteristics:

File Information

Size
36K
SHA-1
7d7a5b8713ce245cbb43013d4f223c96e37bfd18
MD5
3ee905928a2f686f59afaa6c1fc60230
CRC-32
e70d101d
File type
application/x-ms-dos-executable
First seen
2012-03-31

Runtime Analysis

Copies Itself To
  • C:\WINDOWS\sadrive32.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Direct3D\MostRecentApplication
    Name
    sadrive32.exe
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
    Microsoft Driver Setup
    C:\WINDOWS\sadrive32.exe
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Microsoft Driver Setup
    C:\WINDOWS\sadrive32.exe
Processes Created
  • c:\windows\sadrive32.exe
DNS Requests
  • haaaaaaaaa.homler.net

download Try Sophos products for free
Download now