| Malware name | Script.AutoRun.AL | | Type | Worm | | Affected platform | Win32 | | Media-Type | application/rar | | MD5 checksum | 7B1B3E9C68A13543210B4634D5C50C77 | | Static file | no | | Filesize | 4,262 Bytes | Alias names (also known as) | | Sophos | VBS/Autorun-AO | | McAfee | W32/Autorun.worm.al | | CA ETrust | VBS/SillyAutorunScript.B |
| | Side effects | Drops a file | | Propagation | No own spreading routine |
|
Description:
Files
It copies itself to the following locations:
• %WINDIR%\.vbe
• %SYSDIR%\.vbe
The following file is created:
–
%malware execution directory%\012.vbs This is a non malicious text file with the following content:
• createobject("wscript.shell").run ".vbe"
Furthermore it gets executed after it was fully created.