Sophos

W32/Autorun-CH

Aliases
  • Trojan.Win32.Autoit.bh
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Included in our products from April 2008 (4.29)
Protection available since 24 March 2008 10:10:14 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-CH is a worm for the Windows platform.

When first run W32/Autorun-CH copies itself to the User folder and creates the following files:

<User>\Application Data\tr2.bmp
<Temp>\aut1.tmp

The following registry entry is set:

HKCU\Control Panel\desktop
wallpaper
<User>\Application Data\tr2.bmp

W32/Autorun-CH spreads by copying itself to removable media as <drive>\explorer.exe. To run this file, <drive>\autorun.inf is also created.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer