WORM_AUTORUN.HCE

 Analysis by: Roland Marco Dela Paz

 ALIASES:

Kaspersky: Trojan.Win32.VB.afvv

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Worm

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Copies itself in all available physical drives, Propagates via removable drives


This worm uses the default Windows folder icon to trick users into opening the file. Double-clicking the file executes this malware.

  TECHNICAL DETAILS

File Size:

23,552 bytes

File Type:

PE

Memory Resident:

Yes

Initial Samples Received Date:

15 Mar 2011

Installation

This worm uses the default Windows folder icon to trick users into opening the file. Double-clicking the file executes this malware.

Propagation

This worm searches for folders in all physical and removable drives then drops copies of itself inside the folder as {folder name}.EXE.

It drops the following copy of itself in all physical and removable drives:

  • .exe

NOTES:

It sets the attribute of found folders to "Hidden" so that users are lured to click its dropped copy instead of the original folder.