Name : Worm:W32/AutoRun.NOI
Detection Names : Worm.Win32.AutoRun.noi
Aliases : W32/Autorun-jl (Sophos)
Generic.dx trojan (McAfee)
WORM_AUTORUN.RC (Trend Micro)
W32.SillyFDC (Symantec)
Worm:Win32/Emold.C (Microsoft)
Type: Worm
Category: Malware
Summary
AutoRun worm.
Additional Details
Worm.Win32.AutoRun.noi creates a copy of itself as the following:
C:\Program Files\Microsoft Common\wuauclt.exe
It creates the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
Debugger = "%ProgramFiles%\Microsoft Common\wuauclt.exe
Note: The key is created for automatic execution when explorer.exe is launched.
http://www.f-secure.com/v-descs/worm_w32_autorun_noi.shtml
Was this reply helpful? (0) (0)
Staff pick