Selected viruses, spyware, and other threats: sorted alphabetically
Win32/Autoit.GR
|
Short description
Win32/Autoit.GR is a worm that spreads by copying itself into certain folders.Installation
When executed, the worm copies itself into the following location:- %system%SVCHo5T.EXE
- [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversion
Run]
"SVCHO5T.EXE" = "%system%SVCHO5T.EXE"
Spreading
The worm searches local drives for files with the following file extensions:- *.*
The worm also searches for folders on local drives.
When the worm finds a folder matching the search criteria, it creates a new copy of itself.
The name of the new file is based on the name of the folder found in the search.
The filename has the following extension:
- .exe
- %foundfolder%, %system%%foundfolder%
Spreading on removable media
The worm copies itself into the root folders of removable drives using the following filename:- CD-CNTT-k43.exe
- Daitu-Tn.txt
Other information
The worm may set the following Registry entries:- [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
PoliciesExplorer]
"NoFolderOptions" = 1
