| General information of W32/Autorun.worm.zf.gen | |
| Name: | W32/Autorun.worm.zf.gen (Free Scan) |
| Affected OS: | Windows NT/2000/XP/Vista |
| Category: | Worm |
| Risk level : |
![]() |
This detection is for a worm. It attempts to spread by creating an autorun.inf file, which will run the worm automatically on systems which use the drives that are set to Autorun.
When run, the worm copies itself to the %Windir%\system32 folder and hides itself there. In addition it drops its autorun.inf file in the same location.
The worm tries to connect the following URLs:
It makes the following changes to the registry. Notably, it changes registry values to start itself when Windows restarts.
Keys added:
Values modified: