Sophos

W32/Autorun-BB

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 5 February 2008 20:13:37 (GMT)
Last updated 8 February 2008 10:22:57 (GMT)
Detected by All Sophos products

Action

More Information

When the worm is executed it attempts to copy itself as test.vbs to the system folder. It also attempts to copy itself to the root of fixed, remote and removable drives (excluding drives A: and B:) as test.vbs.

The worm also attempts to copy the following files:

test.bat
test.reg
autorun.inf
autoicon.ico

The following registry entries may be set:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"Userinit"="userinit.exe,test.bat"

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
"ShowSuperHidden"=dword:00000000

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer