Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2008 (4.31) |
| Protection available since | 2 June 2008 08:17:57 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/AutoRun-EO is a worm for the Windows platform.
When run W32/AutoRun-EO copies itself to
<System>\drivers\spools.exe
<Documents and Settings>\<User>\cftmon.exe
<Root>\porno.exe
The following registry entries are set to run the worm on startup:
HKCR\exefile\shell\open\command
(default)
<Documents and Settings>\<User>\cftmon.exe \"%1\" %*
HKLM\SYSTEM\CurrentControlSet\Services\Schedule
ImagePath
<System>\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
autoload
<Documents and Settings>\<User>\cftmon.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
<ntuser>
<System>\drivers\spools.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
autoload
<Documents and Settings>\<User>\cftmon.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<ntuser>
<System>\drivers\spools.exe
W32/AutoRun-EO spreads via removable shared drives by copying itself to <Root>\autorun.exe and creating the file <Root>\autorun.inf. The file <Root>\autorun.inf (also detected as W32/AutoRun-EO ) is designed to run the worm when the infected drive is connected to an uninfected computer.
W32/AutoRun-EO includes functionality to download code from the internet.
