Sophos

W32/AutoRun-RR

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Included in our products from February 2009 (4.38)
Protection available since 5 December 2008 11:32:37 (GMT)
Last updated 8 December 2008 01:22:12 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-RR is a worm for the Windows platform.

When run W32/AutoRun-RR copies itself to <System>\myrvc.exe and creates the files:
<System>\SysResources.dat - can be deleted
<System>\dotnetfx.dll - also detected as W32/AutoRun-RR

W32/AutoRun-RR spreads via removable shared drives (like USB keys) by copying itself as <Root>\Softwares.exe and creating the file <Root>\autorun.inf (detected as Mal/AutoInf-A).

The following registry entries are set:

HKCU\Software\Microsoft\Internet Explorer\Main
FormSuggest PW Ask
yes

HKCU\Software\Microsoft\Internet Explorer\Main
FormSuggest Passwords
yes

HKCU\Software\Microsoft\Internet Explorer\Main
Use FormSuggest
yes

HKLM\SOFTWARE\Microsoft\DotNetRecovery
(default)
A

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
.Net Recovery
rundll32.exe dotnetfx.dll,repair

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sysanalysing
<System>\myrvc.exe %

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer