This malicious VBScript propagates by dropping copies of itself in physical and removable drives using the file name
.MS32DLL.DLL.VBS.
It also drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
This VBScript arrives on a system as a file dropped by other malware, or downloaded by an unsuspecting user when visiting malicious Web sites. It may also arrive via removable drives.
Upon execution, it drops the following copies of itself in the Windows folder. The said files have attributes set to
Read-Only,
Hidden, and
System to avoid easy detection. It modifies the registry to enable
Autoplay feature on all drives and hide files with certain file name extensions.[/b]
Bookmarks