Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | May 2007 (4.17) |
| Protection available since | 24 March 2007 03:01:34 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Wekode-A is a worm for the Windows platform.
W32/Wekode-A copies itself to the root folder of writable drives, and adds an autorun.inf file in an attempt to execute itself when the drive is mounted.
W32/Wekode-A alters the following registry entries:
<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run\kernel32
<System>\kernel32.dll.vbs
<HKCU>\Software\Microsoft\Internet Explorer\Main\Window Title
Hacked by 8BITS
