Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 11 January 2009 15:46:40 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Autorun-TQ is a worm that copies itself to removable storage devices.
W32/Autorun-TQ copies itself together with an autorun.inf file that specifies the worm should be run automatically.
The worm also copies itself to the Application Data folder and creates the following registry entry so it is run on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<filename of worm>
<pathname of worm>
The worm could be encountered under any filename, but has been seen with the filename Slk11.exe.
The following registry entry is also created:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2
