|W32.Ainesey.A@mm is a mass-mailing worm that sends a copy of itself to all the email addresses gathered from the computer.
The Subject, Body, and Attachment name in the email vary.
Creates a copy of itself as %Windir%\Msiexec32.exe.
Creates the file, %Windir%\Winexec.exe.vbs, and executes it.
This file is detected as W32.Ainesey.A@mm!vbs.
Adds the values:
to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
Searches local hard drives and network drives for files with the following extensions and overwrites them:
.vbs; .vbe; .js; .jse; .css; .wsh; .sct; .hta; .mp3; .wma
The worm appends a .vbs extension to .js, .jse, .css, .wsh, .sct, .hta, .mp3, and .wma files.
Adds the values to some registry keys which decreases security settings in Microsoft Word, Excel, and PowerPoint.
Emails a copy of itself to the email addresses gathered from the system.
Automatic removal: Use antivirus (also check How To Remove section)Startup Optimizer to remove it from startup.