Sophos

W32/Autorun-TQ

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 11 January 2009 15:46:40 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Autorun-TQ is a worm that copies itself to removable storage devices.

W32/Autorun-TQ copies itself together with an autorun.inf file that specifies the worm should be run automatically.

The worm also copies itself to the Application Data folder and creates the following registry entry so it is run on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<filename of worm>
<pathname of worm>

The worm could be encountered under any filename, but has been seen with the filename Slk11.exe.

The following registry entry is also created:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer