Sophos

W32/Autorun-CP

Aliases
  • W32/Downldr2.BNI
  • Trojan-Downloader.Win32.Delf.azm
  • Generic.fe
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 6 April 2008 14:08:35 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-CP is a worm for the Windows platform.

W32/Autorun-CP attempts to spread by coping itself to removable storage devices as the file QQDoctor.exe and creates a hidden autorun.inf to launch QQDoctor.exe automatically when the device is plugged in. The file autorun.inf should be deleted.

When first run W32/Autorun-CP copies itself to <System>\QQUpdateCenter.exe and creates the file <System>\winlog.txt. This file can be deleted.

The file QQUpdateCenter.exe is registered as a new system driver service named "RaccMgr", with a display name of "RaccMgr" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\RaccMgr

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer