Threat Database Worms W32/AutoRun-AOG

W32/AutoRun-AOG

By Domesticus in Worms

W32/AutoRun-AOG is a computer worm for the Windows platform. W32/AutoRun-AOG spreads via removable storage devices, copying itself to these shared drives and then executing once the drives are connected to an uninfected computer. W32/AutoRun-AOG may also attempt to spread through network shares by cataloging existing network drives on the computer and copying itself as True_Love.exe.

File System Details

W32/AutoRun-AOG may create the following file(s):
# File Name Detections
1. \MsRun32.exe
2. \autorun.ini

Registry Details

W32/AutoRun-AOG may create the following registry entry or registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\SystemDisableRegistryTools 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell Explorer.exe MsRun32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ExplorerNofolderOptions 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Run MSN Messengger \MsRun32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares shared\True_Love.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\SystemDisableTaskMgr 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL CheckedValue 0

Trending

Most Viewed

Loading...