Sophos

W32/Autorun-FB

Aliases
  • Worm:Win32/Hamweq.A
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 12 June 2008 18:47:26 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Autorun-FB is a worm for the Windows platform.

When run, W32/Autorun-FB copies itself to the following folder:

C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\<filename>.exe

The following registry entry is set to run the worm at startup:

HKLM\\Software\Microsoft\Active Setup\Installed Components\
{18B0E5C2-99CB-11CF-AYX5-00401C648513}\
StubPath
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\<filename>.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer