Antivirus and Security Software from Sophos

Sophos blogs

Troj/Autorun-NG

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Chat programs
Affected operating systems Windows
Protection available since 31 October 2008 07:22:16 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing Trojans.


User should delete the scheduled task named "At1".

More Information

Troj/Autorun-NG copies itself to <System>\chrome.exe and <Windows>\chrome.exe.

Troj/Autorun-NG schedules itself to run every day at 9:00AM.

Troj/Autorun-NG sets the following registry values:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools

Troj/Autorun-NG creates the following registry value

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\chrome.exe

Troj/Autorun-NG changes the default page, the default search page and the start page for Internet Explorer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer