Skip to main content

Worm:VBS/AutoRun.B

Classification

Category:

Malware

Type:

Worm

Aliases:

  • VBS/Autorun.worm.k
  • Virus.VBS.AutoRun.b
  • Type_vbs_autorun

Summary

Worm:VBS/AutoRun.B is a worm that spreads by copying itself to local hard drives, network drives, and removable drives. It has no other functionality.

Removal

Technical Details

Propagation

The worm contains four files:

  • __.vbs
  • __.reg
  • __.bat
  • autorun.inf

The first file is the worm's Visual Basic Script file.

The autorun.inf file causes the __.vbs file to be executed when an infected drive is accessed with a computer that has autorun enabled on the drive in question.

The script copies all four files to the root of local hard drives, network drives, and removable drives not labeled A:\ or B:\. The four files are also copied under %windir%\system32.

Execution

The _.reg and _.bat files are detected as Trojan.Win32.Zapchast.ee.

If the script isn't being run from the %windir%\system32 location and therefore hasn't yet been installed, it executes the __.bat file.

The batch file (__.bat) installs the worm by creating the following registry entry to execute itself each time the computer is started:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit = userinit.exe,__.bat

The batch file can make the registry changes by adding the contents of __.reg in to the registry. If the __.bat file was executed by the registry entry, it then runs the script file.

The batch file also sets the file attributes for all four files to hidden, system, read-only and archive.

The worm also tries to alter this registry entry:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ShowSuperHidden

This alteration is an attempt to make hidden files invisible in Windows Explorer.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.