Sophos

W32/Autorun-DB

Aliases
  • WORM_DELF.FKZ
  • Worm.Win32.AutoIt.x
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 15 April 2008 14:12:44 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-DB is a worm for the Windows platform.

When first run W32/Autorun-DB copies itself to:

<Windows>\regsvr.exe
<System>\regsvr.exe
<System>\svchost .exe

and creates the following files:

<System>\28463\svchost.001
<System>\28463\svchost.exe
<System>\setting.ini
<System>\setup.ini

The file svchost.exe is detected as Ardamax keylogger application. The file setup.ini will autorun regsvr.exe when removable storage device is accessed and should be deleted. The rest of the files are not malicious and also can be deleted.

The following registry entry is created to run W32/Autorun-DB on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
svchost Agent
<System>\28463\svchost.exe

The following registry entry is changed to run regsvr.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe regsvr.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer