March 18, 2010

6/8: W32/AutoRun-AEO Changes Registries

W32/AutoRun-AEO is a worm for the Windows platform.

When first run W32/AutoRun-AEO copies itself to:

%System%services.exe %Documents and Settings%userStartMenuProgramsStartupkbddrv32.com

Registry entries are set (appended - modified) include the following:

HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon Shell " C:\WINDOWS\services.exe"

More information can be found at this Sophos page.

1
IT Offers

Partners