Sophos

W32/Autorun-BA

Aliases
  • W32/Autorun.worm.g
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2008 (4.27)
Protection available since 2 February 2008 17:08:18 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-BA is a worm for the Windows platform.

W32/Autorun-BA spreads by copying itself to the available mapped drives and shared folders with the following filenames:

_Fichiers.exe
_Saves.exe
\MisVh55.exe

The following registry entry is set:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
\MisVh55.exe

The worm modifies a number of registry settings including the following:

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
0

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore DisableConfig
0

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Hidden
2

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer