Sophos

W32/AutoRun-IX

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2008 (4.34)
Protection available since 8 September 2008 06:54:12 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-IX is a worm for the Windows platform that spreads via removable shared drives.

When run W32/AutoRun-IX copies itself to:
<Program Files>\<random characters>.exe
<Program Files>\Common Files\Microsoft Shared\<random characters>.exe
<Program Files>\Common Files\System\<random characters>.exe

W32/AutoRun-IX also creates the file <Program Files>\<random characters>.inf (detected as W32/AutoRun-IX).

The following registry entries are set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random characters>
<Program Files>\Common Files\Microsoft Shared\<random characters>.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random characters>
<Program Files>\Common Files\System\<random characters>.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer