Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 25 April 2007 07:28:03 (GMT) |
| Last updated | 26 April 2007 09:03:18 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing infected executable files.
More Information
W32/Liji-A is a virus for the Windows platform.
When run W32/Liji-A creates the file <Temp>\<random numbers>.bmw. This file is also detected as W32/Liji-A.
Once installed W32/Liji-A attempts to infect file executables. The infected files will then attempt to download files from a remote website and run it. The infected files are also detected as W32/Liji-A.
W32/Liji-A also attempts to spread by copying itself via:
- network shares protected by weak passwords, as the filename krdown.exe
- removeable shared drives, as the filename <Root>\autorunx.exe. It does this by creating the file <Root>\autorun.inf that contains instructions to run the virus when the removeable drive is connected to an uninfected computer.
W32/Liji-A also copies itself to <System>\spool\svchost.exe and creates the following registry entry to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wlinles
<System>\spool\svchost.exe
