Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 28 March 2006 14:26:39 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Alcra-F is a worm for the windows platform.
W32/Alcra-F uses file sharing applications to spread.
W32/Alcra-F typically arrives with the filename Setup.exe. W32/Alcra-F is a worm for the windows platform.
W32/Alcra-F uses file sharing applications to spread.
W32/Alcra-F typically arrives with the filename Setup.exe.
When first run W32/Alcra-F displays a dialog box with the text "Setup", "Welcome to the Setup Wizard ...".
The dialog then gives a fake error message, before closing.
W32/Alcra-F creates the folder <Program Files>\winsupdater and copies itself to this folder as
a.temp
winsupdater.exe
winsupdater.exe has the hidden file attribute and similarly the
<Program Files>\winsupdater\ folder is a hidden folder.
W32/Alcra-F creates the following files:
<root folder>\at.exe
<Program Files>\winsupdater\a.zip
Where the a.zip file contains a copy of the Setup.exe.
The file at.exe is detected as W32/Rbot-CVY.
When first run, W32/Alcra-F creates the following registry entry to ensure that it is run when an infected system starts:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winsupdater
<Program Files>\winsupdater\winsupdater.exe /auto

