Home / malwarePDF  

Worm:VBS/Basack!inf


First posted on 16 May 2013.
Source: Microsoft

Aliases :

Worm:VBS/Basack!inf is also known as VBS/AutoRun-FG (Sophos).

Explanation :



When run, Worm:VBS/Basack.A creates the following files on targeted removable drives:

  • <removable drive>:\\autorun.inf- this is the file detected by our security products as Worm:VBS/Basack!inf
  • <removable drive>:\\system.vbs - this is a copy of the worm


The autorun.inf file contains instructions for the operating system so that when the removable drive is accessed from another computer supporting the Autorun feature, the worm is launched automatically.

This is particularly common malware behavior, generally used in order to spread malware from computer to computer.

It should be noted that autorun.inf files on their own are not necessarily a sign of infection, as they are used by legitimate programs and installation media.



Analysis by Hyun Choi

Last update 16 May 2013

 

TOP