| Malware name | Script.Autorun.VF | | Type | Script | | Affected platform | Win32 | | Media-Type | none | | MD5 checksum | 62DB801E06C4ED65193FFD7A07E686BC | | Static file | no | | Filesize | 18,281 Bytes | Alias names (also known as) | | Sophos | VBS/Enc-B | | McAfee | VBS/Autorun.worm.k | | CA ETrust | VBS/RaiderVIII.D |
| | Propagation | Mapped network drives |
|
Description:
Files
It copies itself to the following locations:
• %SYSDIR%\.vbe
• %SYSDIR%\wbem\.vbe
•
%drive%:\.vbe
The following files are created:
–
%drive%:\autorun.inf This is a non malicious text file with the following content:
•
%code that runs malware% Registry
The following registry key is added in order to run the process after reboot:
– [HKLM\software\microsoft\windows\currentversion\policies\explorer\
run]
•
%computer name% = .vbe
The following registry key is added:
– [HKLM\software\
%computer name%]
•
%system-dependent% The following registry key is changed:
Various Explorer settings:
– [HKCU\software\microsoft\windows\currentversion\explorer\advanced]
New value:
• showsuperhidden = 0