









 |
W32/AutoRun.Cpi Worm
| Name |
W32/AutoRun.Cpi Worm |
| Aliases |
TR/Crypt.CFI.Gen, Worm.Autorun.Delf.H, Worm.AutoRun.aij, Win32.AutoRun.cpi, Worm.Win32.AutoRun.cpi, W32/ManClick.A.worm, W32/Autorun-BC |
| Discovered on |
March 15, 2008 |
Virus Information - W32/AutoRun.Cpi Worm:
W32/AutoRun.Cpi is a worm. The worm will infect Windows systems and spreads through removable drive and network drives.
The worm will arrive as a dropped file from the network or removable drive.
Upon execution, the worm copies itself as auto.exe, autorun.inf in Root of windows installed folder, system.exe in Windows folder and Explorer.exe in Startup folder.
The worm modifies registry at the following location to load itself during each startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
It also copies auto.exe and autorun.inf in the removable drives.
The worm modify windows registry to disable Folder options and Windows Registry editor.
The worm sets home page of Internet Explorer to http://cli[removed]nu.com
The affected system will not boot in safe mode.
The worm is capable of disabling some security related applications.
The worm terminate running processes like Command Prompt or Task Manager in the affected system.

|