









 |
W32/AutoRun.CFT Worm
| Name |
W32/AutoRun.CFT Worm |
| Aliases |
W32/Autorun.E, Worm.Autorun.VCF, Win32.AutoRun.cft, Win32/SillyAutorun.CK, W32/AutoRun.BNE, W32/Autorun.MR.worm, Worm.Win32.Autorun.jsz, W32.SillyFDC, Worm.Autorun.DG, Worm.AutoRun.cft |
| Discovered on |
August 08, 2008 |
Virus Information - W32/AutoRun.CFT Worm:
W32/AutoRun.CFT is a worm. The worm will infect Windows systems.
The worm will arrive as a dropped file from the network or removable drive.
Upon execution, the worm copies itself as Logonsvc.exe, NetLogonsvc.exe in Windows System folder and Autorun.inf, USBoot.exe in Root of windows installed folder.
The worm modifies registry at the following location to load itself during each startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
It also copies Funny UST Scandal.exe, xmss.exe and autorun.inf in the removable drives.
It also copies USBoot.exe and Autorun.inf in the removable drives.
We are detecting NetLogonsvc.exe as W32/Agent.Bxt.Dropper.Trojan.

|