WORM_AUTORUN.INF


 ALIASES:

Microsoft : Virus:Win32/Small.R; Mcafee : Generic BackDoor.j; Fortinet : W32/SillySvc.J!tr.bdr

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Worm

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This worm may be unknowingly downloaded by a user while visiting malicious websites.

  TECHNICAL DETAILS

File Size:

106,496 bytes

File Type:

EXE

Memory Resident:

Yes

Initial Samples Received Date:

28 Jul 2009

Arrival Details

This worm may be unknowingly downloaded by a user while visiting malicious websites.

Installation

This worm drops the following copies of itself into the affected system:

  • %Windows%\system\svchost.exe

(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)

It creates the following folders:

  • %Windows%\system\_sv_CMD_

(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)

Autostart Technique

This worm modifies the following registry entries to ensure it automatic execution at every system startup:

HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\
WINDOWS NT\CURRENTVERSION\Winlogon
Userinit = userinit.exe,%Windows%\System\svchost.exe

(Note: The default value data of the said registry entry is %System%\userinit.exe,.)