We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:VBS/Autorun.AG
Aliases: Virus.VBS.AutoRun.ad (Kaspersky) Worm/AutoRun.CH (AVG) VBS/Slogod.AP (CA) VBS/AutoRun.BK (ESET) VBS/Autorun.worm.k (McAfee) Worm.Script.VBS.Autorun.c (Rising AV) VBS/Solow-Gen (Sophos) VBS_PEENAS.A (Trend Micro)
Summary
Recovering from recurring infections on a network
- Ensure that an antivirus product is installed on ALL computers connected to the network that can access or host shares.
- Ensure that all available network shares are scanned with an up-to-date antivirus product.
- Restrict permissions as appropriate for network shares on your network. For more information on simple access control, please see: http://technet.microsoft.com/library/bb456977.aspx.
- Remove any unnecessary network shares or mapped drives.
Additional remediation instructions for Worm:VBS/Autorun.AG
- Changing your Internet Explorer Home Page:
- For Windows 7: http://windows.microsoft.com/en-us/windows7/Change-your-Internet-Explorer-home-page
- For Internet Explorer 7 and 8 in Windows Vista: http://windows.microsoft.com/en-US/windows-vista/Change-your-Internet-Explorer-home-page
- For Internet Explorer 6: http://support.microsoft.com/kb/252464
- Restoring your System Registry:
- For Windows 7: http://windows.microsoft.com/en-us/windows7/Back-up-the-registry
- For Windows Vista: http://windows.microsoft.com/en-US/windows-vista/Back-up-the-registry
- For Windows XP: http://support.microsoft.com/kb/322756/
- Correctly disabling Autorun in Windows: http://support.microsoft.com/kb/953252
- Using the system's recovery options:
- For Windows XP: Installing and using the Recovery Console in Windows XP
- For Windows Vista: System Recovery Options in Windows Vista
- For Windows 7: System Recovery Options in Windows 7
- For other support and help related articles, go to:
- Windows 7: http://support.microsoft.com/gp/windows7
- Windows Vista: http://support.microsoft.com/ph/11732
- Windows XP: http://support.microsoft.com/ph/1173
- Microsoft Security TechNet Center: http://technet.microsoft.com/security/default.aspx