Selected viruses, spyware, and other threats: sorted alphabetically
Win32/AutoRun.Delf.HH
|
Short description
Win32/AutoRun.Delf.HH is a worm that spreads via removable media. The worm can download and execute a file from the Internet.Installation
When executed, the worm copies itself into the following location:- %windir%SysRegSrvc.exe (558080 B)
- [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
Run]
"MSkip" = "%windir%SysRegSrvc.exe"
- [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
ExplorerAdvanced]
"SuperHidden" = 0
"ShowSuperHidden" = 0
Spreading on removable media
The worm copies itself into the root folders of removable drives using the following filename:- Start.exe
- autorun.inf
Information stealing
The worm collects the following information:- computer name
- user name
- CPU information
Other information
The worm restarts the operating system if there is a window with any of the following strings in the name:- The Wireshark Network Analyzer
The worm contains a list of (2) URLs. The HTTP protocol is used.
The worm can download and execute a file from the Internet.
