Sophos

W32/Autorun-FB

Aliases
  • Worm:Win32/Hamweq.A
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2008 (4.32)
Protection available since 12 June 2008 18:47:26 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-FB is a worm for the Windows platform.

When run, W32/Autorun-FB copies itself to the following folder:

C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\<filename>.exe

The following registry entry is set to run the worm at startup:

HKLM\\Software\Microsoft\Active Setup\Installed Components\
{18B0E5C2-99CB-11CF-AYX5-00401C648513}\
StubPath
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\<filename>.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer