Sophos

W32/Autorun-DC

Aliases
  • WORM_TIHS.A
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 14 April 2008 21:34:34 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-DC is a worm for the Windows platform.

W32/Autorun-DC spreads to other network computers.

When first run W32/Autorun-DC copies itself to:

<Startup>\Empty.pif
<Windows>\Web\printers\prtwebvw.exe
<Windows>\addins\services.exe
<Windows>\java\classes\lsass.exe
<Windows>\mui\smss.exe

and creates the following files:

<Windows>\Autorun.inf
<Windows>\SoftWareProtector\Error_out.pr

The following registry entry is changed to run W32/Autorun-DC on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<Windows>\Addins\services.exe"

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
00

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoFolderOptions
00

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug
Debugger
<Windows>\mui\smss.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer