TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
MAL_OTORUN
Overview

Malware type: Worm

Aliases: W32.Dotex(Symantec), Worm.Win32.AutoRun.ow(Kaspersky), TR/Dldr.Delphi.Gen(Avira), W32/AutoRun.B.gen!Eldorado (generic(F-Prot), W32/Webbew.worm(McAfee)

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Medium

Infection Channel 1 : Propagates via removable drives


Infection Channel 2 : Copies itself in all available physical drives


Description: 

This is the Trend Micro detection for suspicious files that manifest behavior and characteristics similar to WORM_AUTORUN variants. Files detected usually drop a copy of itself and AUTORUN.INF file on physical and removable drives for its propagation and autostart technique.

Since these files commonly arrive and propagate via removable drives, it is important to protect your system by first protecting your removable drive. Below are a number of options that help prevent malware from affecting or starting in your removable drive.

  • Create a folder named AUTORUN.INF that is set to certain attributes to prevent malware from creating its own AUTORUN.INF, as most WORM_AUTORUN variants drops or overwrites a copy of the existing AUTORUN.INF. To do this, you may follow the steps listed here.
  • Enable the write-protect switch on a removable drive to allow read-only access to the removable drive. This switch is available on some removable drives. Enabling the switch prevents malware from being saved on your removable drive.
  • Scan your removable drive with an antivirus application before opening the drive. You can use online tools such as the Trend Micro HouseCall to scan removable drives.

Files using the AUTORUN.INF file, in part, rely on the autorun or autoplay feature in Windows. This feature enables removable media such as CDs and removable drives to start automatically upon insertion or connection to the system. The following option helps prevent the spread of malware on the system.

Modify registry entry to disable the autorun feature. A specific registry entry is related to the autorun feature of Windows systems. To learn how to modify this registry entry, please click here.

If your Trend Micro product detects a file under this detection name, do not execute the file. Delete it immediately especially if it came from an untrusted or an unknown source (e.g., a Web site of doubtful nature). However, if you have reason to believe that the detected file is non-malicious, you can submit a sample for analysis. Detailed analysis will be done on submitted samples, and corresponding removal instructions will be provided, if necessary.

To submit files, please refer to the Solution section.

For additional information about this threat, see:
Solution

Description created: Sep. 1, 2007 6:46:45 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.