W32/Autorun-TQ

Category: Viruses and Spyware Protection available since:11 Jan 2009 14:27:32 (GMT)
Type: Win32 worm Last Updated:11 Jan 2009 14:27:32 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Autorun-TQ is a worm that copies itself to removable storage devices.

W32/Autorun-TQ copies itself together with an autorun.inf file that specifies the worm should be run automatically.

The worm also copies itself to the Application Data folder and creates the following registry entry so it is run on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<filename of worm>
<pathname of worm>

The worm could be encountered under any filename, but has been seen with the filename Slk11.exe.

The following registry entry is also created:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2

download Try Sophos products for free
Download now