









 |
W32/AutoRun.Abt Worm
| Name |
W32/AutoRun.Abt Worm |
| Aliases |
Virus.Win32.AutoRun.abt, w32/autorun.fj.worm, win32/autorun.m, W32/Autorun.worm.g!f9007a93 |
| Discovered on |
January 28, 2008 |
Virus Information - W32/AutoRun.Abt Worm:
W32/AutoRun.Abt is a worm. The worm will infect Windows systems and spreads through removable drive and network drives.
The worm will arrive as a dropped file from the network or removable drive.
Upon execution, the worm copies itself as Funny UST Scandal.exe, xmss.exe, autorun.inf in Windows and Root of windows installed folder.
The worm modifies registry at the following location to load itself during each startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
It also copies Funny UST Scandal.exe, xmss.exe and autorun.inf in the removable drives.
The worm disable the display of hidden files and Autoplay feature on all drives.
The worm terminate running processes like Command Prompt, Task Manager and Process Explorer in the affected system.

|