W32/AutoRun-DG is a worm for the Windows platform.
When run, the worm creates the files:
System\fool(random number).dll
System\ieso(random number).dll
Temp\(random characters).dll
Temp\(random characters).sys
These 4 files are also detected as W32/AutoRun-DG.
W32/AutoRun-DG spreads via removable drives by creating the file Root\autorun.inf (detected as W32/AutoRun-DG) and copying the worm to Root\n2.bat. The autorun.inf is designed to run the worm when the drive is connected to an uninfected computer.
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0
Registry entries are created under:
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\
(default)
IEHlprObj Class
More information can be found at this Sophos page.
Loading Comments...