WORM_SMALL.CBP
Overview

QUICK LINKS  

Understanding New Pattern Format |

Malware type: Worm

Aliases: Worm.Win32.Small.i (Kaspersky), W32/CWT.worm (McAfee), W32.SillyDC (Symantec), Worm/Small.I.43 (Avira), Mal/Generic-A (Sophos), Worm:Win32/Small (Microsoft)

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:

Low

Reported infections:

Low

Damage potential:

Low

Distribution potential:

High

Infection Channel 1 : Propagates via removable drives


Infection Channel 2 : Copies itself in all available physical drives


Description: 

This worm propagates by copying itself to removable drives and in all available physical drives. However, it skips floppy drives.

It drops AUTORUN.INF in an affected drive's root folder. The said file, which contains certain strings, enables its copy named DRIVEINFO.EXE to execute whenever the affected drive is accessed. It then creates the subfolder Recycled, where it drops a copy of itself named DRIVEINFO.EXE, in the affected drive's root folder.

Note that this worm runs only if its copy is located in a folder named either Recycled or system32.

For additional information about this threat, see:
Solution
Technical Details
Statistics

Description created: Jul. 18, 2006 2:42:12 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.

Quick Links