Sophos

W32/AutoRun-DO

Aliases
  • W32/Autorun.worm.i.gen
  • Virus.Win32.AutoRun.lr
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 23 April 2008 19:36:06 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-DO is a worm for the Windows platform.

When first run W32/AutoRun-DO copies itself to the <temp> folder and to the following files:

<Temp>\Tmp.com
<User>\Local Settings\explorer.exe
<User>\Local Settings\services.exe
<User>\Local Settings\smss.exe
<User>\Local Settings\svchost.exe
<User>\Local Settings\winlogon.exe
<Windows>\fonts\font.bat
<Windows>\repclient1.exe
<System>\regedit.exe
<System>\wininit.com
<System>\REPCLIENT1.exe
<System>\command.cmd
<System>\msdp32.dll
<Windows>\win.pif

The following registry entries are created to run regedit.exe, msdp32.dll and win.pif on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
run
explorer.exe <System>\regedit.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
(Default)
win.com <System>\msdp32.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
REPCLIENT1
<Windows>\win.pif

The following registry entry is changed to run wininit.com on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
System
<System>\wininit.com

The file font.bat is registered as a new system driver service named "MsNet", with a display name of "MsNet Service" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\MsNet

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
<Root>\DOCUME~1\<user>\LOCALS~1\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
(Default)
<Root>\DOCUME~1\<user>\LOCALS~1\winlogon.exe

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
GPO-ID
LocalGPO

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
SOM-ID
Local

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
FileSysPath
<System>\GroupPolicy\User

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
DisplayName
Local Group Policy

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0
GPOName
Local Group Policy

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0\0
Script
<Windows>\Web\Picture.exe

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0\0
ExecTime
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System
<Root>\DOCUME~1\REPCLI~1\LOCALS~1\svchost.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Root>\DOCUME~1\REPCLI~1\LOCALS~1\smss.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer