WORM_AUTORUN.INF
Microsoft : Virus:Win32/Small.R; Mcafee : Generic BackDoor.j; Fortinet : W32/SillySvc.J!tr.bdr
Windows 2000, XP, Server 2003
Threat Type: Worm
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This worm may be unknowingly downloaded by a user while visiting malicious websites.
TECHNICAL DETAILS
106,496 bytes
EXE
Yes
28 Jul 2009
Arrival Details
This worm may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This worm drops the following copies of itself into the affected system:
- %Windows%\system\svchost.exe
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
It creates the following folders:
- %Windows%\system\_sv_CMD_
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
Autostart Technique
This worm modifies the following registry entries to ensure it automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\
WINDOWS NT\CURRENTVERSION\Winlogon
Userinit = userinit.exe,%Windows%\System\svchost.exe
(Note: The default value data of the said registry entry is %System%\userinit.exe,.)