Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 15 May 2008 18:25:09 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
VBS/Autorun-EC is a worm that spreads by copying itself into the root folder of fixed and removable drives with a filename virus.vbs.
The worm also copies itself to files
<System>\wbem\.vbe
and
<Windows>\system32\.vbe
VBS/Autorun-EC contains code to communicate with a remote server using HTTP protocol.
The worm looks for process names related to security software and attempt to terminate them.
The following registry entries may be affected when the worm infects the system:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
HKLM\SOFTWARE\EXAMPLEPC\til
HKLM\SOFTWARE\EXAMPLEPC\tjs
HKLM\SOFTWARE\EXAMPLEPC\djs
HKLM\SOFTWARE\EXAMPLEPC\ded
HKLM\SOFTWARE\EXAMPLEPC\tgs
HKLM\SOFTWARE\EXAMPLEPC\oer
HKLM\SOFTWARE\EXAMPLEPC\atd
The worm creates a scheduled task to regularly run file .vbe.
