Sophos

W32/Autorun-F

Aliases
  • Trojan-Spy.Win32.Bancos.adk
  • W32/Autorun.worm.f
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2007 (4.24)
Protection available since 22 October 2007 19:18:48 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-F is a worm for the Windows platform which spreads by copying itself to removable devices.

W32/AutoRun-F is a worm for the Windows platform which spreads by copying itself to removable devices.

When first run W32/Autorun-F copies itself to:

<Common Files>\taskmmgr.exe
<Root>\chkdisk.exe
<System>\Svchost.EXE

and creates the following files:

<Root>\autorun.inf
<System>\Intro.avi

The following registry entries are created to run taskmmgr.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Svchost
<Common Files>\taskmmgr.EXE

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TasKmgr
<Common Files>\taskmmgr.EXE

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer