W32/Autorun-TQ is a worm that copies itself to removable storage devices.
W32/Autorun-TQ copies itself together with an autorun.inf file that specifies the worm should be run automatically.
The worm also copies itself to the Application Data folder and creates the following registry entry so it is run on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<filename of worm>
<pathname of worm>
The worm could be encountered under any filename, but has been seen with the filename Slk11.exe.
The following registry entry is also created:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2