Sophos

W32/Shahrokh-A

Aliases
  • Worm.Win32.AutoRun.dpc
  • Win32/AutoRun.MC
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 5 May 2008 23:23:46 (GMT)
Detected by All Sophos products

Action

More Information

When first run W32/Shahrokh-A creates the following files:

<System>\explorer.exe - copy of itself
<System>\service.exe - copy of itself
<System>\tmp.exe - copy of itself
<Root>\autorun.exe - copy of itself
<System>\autorun.inf - can be safely deleted

W32/Shahrokh-A spreads via removable media by creating the following files on each drive it finds on the computer:

<Root>\autorun.exe - copy of itself
<Root>\Shahrokh.exe - copy of itself
<Root>\autorun.inf - can be safely deleted

W32/Shahrokh-A creates the following registry entry to start itself:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Network Services
<System>\Service.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer