Sophos

W32/AutoRun-RS

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2009 (4.38)
Protection available since 5 December 2008 11:32:37 (GMT)
Last updated 4 January 2009 11:46:18 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-RS is a worm for the Windows platform.

When run W32/AutoRun-RS copies itself to:
<Windows>\data.exe
<System>\data.exe
<System>\test.exe

and creates the file <System>\dotnetfx.dll - detected as W32/AutoRun-RS

W32/AutoRun-RS sets the following registry entries:

HKLM\SOFTWARE\Microsoft\DotNetRecovery
(default)
A

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
.Net Recovery
rundll32.exe dotnetfx.dll,repair

W32/AutoRun-RS spreads via removable shared drives by copying itself to <Root>\1864.exe and creating the file <Root>\autorun.inf (detected as W32/AutoRun-RS).

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer