W32.Imaut.CN

W32.Imaut.CN is a worm that will propagate on unsecured network-shared folders and drives. It also spreads by means of malicious links sent out from an infected computer. W32.Imaut.CN will connect to a remote computer and download malware files and codes.

Alias: W32/Sohana-AX, W32/Sohana-AZ, W32/Sohana-BA, Win32/Spideyit.A, W32/AutoRun-HA, W32/Imaut-F, W32/AutoIt-HI

Damage Level: Low

Systems Affected: Windows 95/98/Me, Windows NT/2000/Server 2003/, Windows XP/Vista

Additional Information:

Characteristics

  • The worm will alter Windows registry entries so that it runs on each Windows boot up.
  • It is capable of concealing its presence on the infected computer.
  • W32.Imaut.CN will check for any shared folders and makes a copy of itself whenever possible.
  • To automatically run the worm if drive is accessed, it will create an autoun.inf file on same location.
  • In will end processes containing strings such as game_y.exe and cmder.exe.

Distribution

  • The worm will send message containing malicious link to a random contacts gathered on infected computer.
  • It copies itself to network shared drives and removable drives.

What to do next...