Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 15 April 2008 14:12:44 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Autorun-DB is a worm for the Windows platform.
When first run W32/Autorun-DB copies itself to:
<Windows>\regsvr.exe
<System>\regsvr.exe
<System>\svchost .exe
and creates the following files:
<System>\28463\svchost.001
<System>\28463\svchost.exe
<System>\setting.ini
<System>\setup.ini
The file svchost.exe is detected as Ardamax keylogger application. The file setup.ini will autorun regsvr.exe when removable storage device is accessed and should be deleted. The rest of the files are not malicious and also can be deleted.
The following registry entry is created to run W32/Autorun-DB on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
svchost Agent
<System>\28463\svchost.exe
The following registry entry is changed to run regsvr.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe regsvr.exe
