Sophos

W32/Thili-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2008 (4.31)
Protection available since 11 May 2008 00:50:43 (GMT)
Detected by All Sophos products

Action

More Information

W32/Thili-A is a worm for the Windows platform.

W32/Thili-A may attempt to copy itself to random filenames with a number of extensions, in particular replacing files from the following location in order to run itself automatically on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

W32/Thili-A may also drop a clean data file to a number of random filenames.

The following registry entry is set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskmgr
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer