Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 23 April 2008 13:03:44 (GMT) |
| Last updated | 30 April 2008 14:31:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Malas-C is a worm for the Windows platform.
When first run W32/Malas-C copies itself to:
<Startup>\AdobeUpdate.exe
<User>\Application Data\usrinit.exe
<Temp>\systray.exe
<User>\Local Settings\startup.exe
<Common Files>\AdobeUpdate.exe
<Program Files>\XPCode\SexGame.exe
<Program Files>\XPCode\SexGameList.pif
<Program Files>\XPCode\SexScreenSaver.scr
<Root>\autoply.exe
and creates the following files:
<Root>\Autorun.inf
<Startup>\Adobe Update.lnk
<Program Files>\XPCode\Games.lnk
<Windows>\Tasks\At1.job
<Windows>\Tasks\At2.job
<Windows>\Tasks\At3.job
<Windows>\Tasks\At4.job
The file Autorun.if is detected as Mal/AutoInf-A.
The following registry entry is created to run startup.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SoundMax
<User>\Local Settings\startup.exe
Registry entries are set as follows:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
2
