Sophos

VBS/Autorun-EC

Aliases
  • VBS/Autorun.VF
  • Worm.VBS.Autorun.r
  • VBS_AGENT.AMAF
  • W32/Autorun.worm.cg
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Network shares
Affected operating systems Windows
Included in our products from July 2008 (4.31)
Protection available since 15 May 2008 18:25:09 (GMT)
Detected by All Sophos products

Action

More Information

VBS/Autorun-EC is a worm that spreads by copying itself into the root folder of fixed and removable drives with a filename virus.vbs.

The worm also copies itself to files

<System>\wbem\.vbe

and

<Windows>\system32\.vbe


VBS/Autorun-EC contains code to communicate with a remote server using HTTP protocol.

The worm looks for process names related to security software and attempt to terminate them.

The following registry entries may be affected when the worm infects the system:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run

HKLM\SOFTWARE\EXAMPLEPC\til
HKLM\SOFTWARE\EXAMPLEPC\tjs
HKLM\SOFTWARE\EXAMPLEPC\djs
HKLM\SOFTWARE\EXAMPLEPC\ded
HKLM\SOFTWARE\EXAMPLEPC\tgs
HKLM\SOFTWARE\EXAMPLEPC\oer
HKLM\SOFTWARE\EXAMPLEPC\atd
The worm creates a scheduled task to regularly run file .vbe.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer