









 |
W32/AutoRun.EOR Worm
| Name |
W32/AutoRun.EOR Worm |
| Aliases |
Trojan.Packed.NsAnti, Worm:Win32/Taterf.B |
| Updated on |
February 18, 2010 |
Virus Information - W32/AutoRun.EOR Worm:
W32/AutoRun.EOR is a worm. The worm will infect Windows systems.
Upon execution, the worm drops the following files in Windows\System32 folder:
kavo.exe
kavo0.dll
The worm also drops the following files in root of Windows installed drive:
ceqfqp.bat
autorun.inf
The worm modifies registry at the following location:
HKEY_USERS\S-1-5-21-XXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\Run

|