Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 23 April 2008 19:36:06 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/AutoRun-DO is a worm for the Windows platform.
When first run W32/AutoRun-DO copies itself to the <temp> folder and to the following files:
<Temp>\Tmp.com
<User>\Local Settings\explorer.exe
<User>\Local Settings\services.exe
<User>\Local Settings\smss.exe
<User>\Local Settings\svchost.exe
<User>\Local Settings\winlogon.exe
<Windows>\fonts\font.bat
<Windows>\repclient1.exe
<System>\regedit.exe
<System>\wininit.com
<System>\REPCLIENT1.exe
<System>\command.cmd
<System>\msdp32.dll
<Windows>\win.pif
The following registry entries are created to run regedit.exe, msdp32.dll and win.pif on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
run
explorer.exe <System>\regedit.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
(Default)
win.com <System>\msdp32.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
REPCLIENT1
<Windows>\win.pif
The following registry entry is changed to run wininit.com on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
System
<System>\wininit.com
The file font.bat is registered as a new system driver service named "MsNet", with a display name of "MsNet Service" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\MsNet
Registry entries are set as follows:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
<Root>\DOCUME~1\<user>\LOCALS~1\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
(Default)
<Root>\DOCUME~1\<user>\LOCALS~1\winlogon.exe
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
GPO-ID
LocalGPO
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
SOM-ID
Local
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
FileSysPath
<System>\GroupPolicy\User
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
DisplayName
Local Group Policy
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
GPOName
Local Group Policy
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0\0
Script
<Windows>\Web\Picture.exe
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0\0
ExecTime
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System
<Root>\DOCUME~1\REPCLI~1\LOCALS~1\svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Root>\DOCUME~1\REPCLI~1\LOCALS~1\smss.exe
