General information of W32/Autorun.worm.zf.gen
Name: W32/Autorun.worm.zf.gen (Free Scan)
Affected OS: Windows NT/2000/XP/Vista
Category: Worm
Risk level : risk level 3
Free Spyware Scan
Online computers are easy to be infected by various spyware
  • Fast spyware scanning and removal
  • 100% real-time protection
  • Antivirus/malware protection
Description

This detection is for a worm. It attempts to spread by creating an autorun.inf file, which will run the worm automatically on systems which use the drives that are set to Autorun.

When run, the worm copies itself to the %Windir%\system32 folder and hides itself there. In addition it drops its autorun.inf file in the same location.

The worm tries to connect the following URLs:

  • lemox.myhome.cx
  • zkarmy.dip.jp

It makes the following changes to the registry. Notably, it changes registry values to start itself when Windows restarts.

Keys added:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty

Values modified:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run "csrcs". Data: C:\WINDOWS\system32\csrcs.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell". Data: Explorer.exe csrcs.exe

Related Search
Other spyware: Spyware | Trojan | Backdoor | Worm | Adware | Rootkit | Downloader
.DLL Files:A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
.EXE Files:A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z