Sophos

W32/Autorun-PZ

Aliases
  • W32/Autorun.worm.dq
  • Trojan-Downloader.Win32.VB.gpa
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from January 2009 (4.37)
Protection available since 22 November 2008 05:32:32 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-PZ is a worm for the Windows platform.

When first run W32/Autorun-PZ copies itself to <System>\XP-AA7B56E9.EXE and creates the following files:

<Temp>\e_4\com.run
<Temp>\e_4\dp1.fne
<Temp>\e_4\eAPI.fne
<Temp>\e_4\internet.fne
<Temp>\e_4\krnln.fnr
<Temp>\e_4\RegEx.fnr
<Temp>\e_4\shell.fne
<Temp>\e_4\spec.fne

The file eAPI.fne is detected as Mal/Behav-010. The other files are all detected as W32/Autorun-PZ.

W32/AutoRun-PZ may copy itself to removable drives as the file Recycled.exe and create the file Autorun.inf detected as Mal/AutoInf-A. If there any directories on the removable drive, they will be set to Hidden and W32/AutoRun-PZ will be copied to the drive as <Folder name>.exe.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer