¿Necesita ayuda? Pregunte a la comunidad o contrate a un experto.
Ir a Avira Answers
Virus:VBS/Autorun.VF
Date discovered:18/04/2008
Type:Worm
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Low to medium
Damage Potential:Low to medium
Static file:No
File size:~18.000 Bytes
IVDF version:7.00.03.188 - Friday, April 18, 2008

 General Method of propagation:
   • Mapped network drives


Aliases:
   •  Mcafee: W32/Autorun.worm.cg
   •  Kaspersky: Worm.VBS.Autorun.r
   •  TrendMicro: VBS_AGENT.AMAF
   •  F-Secure: Worm.VBS.Autorun.r
   •  Sophos: VBS/Autorun-EC
   •  Bitdefender: Worm.VBS.Autorun.D


Platforms / OS:
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Access to floppy disk
   • Drops files
   • Registry modification

 Files It copies itself to the following locations:
   • %SYSDIR%\.vbe
   • %SYSDIR%\wbem\.vbe
   • %drive%:\.vbe



The following files are created:

%drive%:\autorun.inf This is a non malicious text file with the following content:
   • %code that runs malware%

 Registry The following registry key is added in order to run the process after reboot:

– [HKLM\software\microsoft\windows\currentversion\policies\explorer\
   run]
   • %computer name% = .vbe



The following registry key is added:

– [HKLM\software\%computer name%]
   • %system-dependent%



The following registry key is changed:

Various Explorer settings:
– [HKCU\software\microsoft\windows\currentversion\explorer\advanced]
   New value:
   • showsuperhidden = 0

Descripción insertada por Andrei Gherman el martes, 17 de junio de 2008
Descripción actualizada por Andrei Gherman el martes, 17 de junio de 2008

Volver . . . .
https:// Esta ventana está cifrada para su seguridad.