Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | March 2008 (4.27) |
| Protection available since | 2 February 2008 17:08:18 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Autorun-BA is a worm for the Windows platform.
W32/Autorun-BA spreads by copying itself to the available mapped drives and shared folders with the following filenames:
_Fichiers.exe
_Saves.exe
\MisVh55.exe
The following registry entry is set:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
\MisVh55.exe
The worm modifies a number of registry settings including the following:
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
0
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore DisableConfig
0
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Hidden
2
