Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | February 2009 (4.38) |
| Protection available since | 5 December 2008 11:32:37 (GMT) |
| Last updated | 8 December 2008 01:22:12 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/AutoRun-RR is a worm for the Windows platform.
When run W32/AutoRun-RR copies itself to <System>\myrvc.exe and creates the files:
<System>\SysResources.dat - can be deleted
<System>\dotnetfx.dll - also detected as W32/AutoRun-RR
W32/AutoRun-RR spreads via removable shared drives (like USB keys) by copying itself as <Root>\Softwares.exe and creating the file <Root>\autorun.inf (detected as Mal/AutoInf-A).
The following registry entries are set:
HKCU\Software\Microsoft\Internet Explorer\Main
FormSuggest PW Ask
yes
HKCU\Software\Microsoft\Internet Explorer\Main
FormSuggest Passwords
yes
HKCU\Software\Microsoft\Internet Explorer\Main
Use FormSuggest
yes
HKLM\SOFTWARE\Microsoft\DotNetRecovery
(default)
A
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
.Net Recovery
rundll32.exe dotnetfx.dll,repair
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sysanalysing
<System>\myrvc.exe %
