Sophos

W32/AutoRun-DT

Aliases
  • Win32/AutoRun.EL
  • WORM_AUTORUN.PA
  • Trojan-Spy.Win32.Delf.auc
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 5 May 2008 23:23:46 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-DT is a worm for the Windows platform.

When first run W32/AutoRun-DT copies itself to:

<Root>\SysInfo2.Dll
<System>\SysInfo.dll

and creates the file <Root>\autorun.inf.

The file SysInfo.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{989D2FEB-5411-4565-8988-1DD2C5263377}
HKCR\CLSID\{989D2FEB-5411-4565-8988-1DD2C5263377}

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer