Sophos

W32/AutoRun-AW

Aliases
  • QHosts.gen
  • Virus.Win32.AutoRun.ain
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2008 (4.27)
Protection available since 25 January 2008 10:34:52 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-AW is a worm for the Windows platform.

W32/AutoRun-AW spreads to other network computers.

When first run W32/AutoRun-AW copies itself to the root and Windows system folders and creates the file Bug1.tmp.

The file Bug1.tmp is detected as W32/SillyFDC-AR.

The following registry entry is created to run W32/AutoRun-AW on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
rising
<System>\<original worm filename>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer