| Malware name | Worm.Autorun.dhl | | Type | Worm | | Affected platform | Win32 | | Media-Type | application/executable | | MD5 checksum | 51050DA73B0B909DEDBA99B9886E165E | | Static file | yes | | Filesize | 63,488 Bytes | Alias names (also known as) | | Sophos | W32/AutoRun-DJ | | McAfee | W32/Autorun.worm.bc | | CA ETrust | Win32/SillyAutorun.JD |
| | Side effects | - Drops files
- Registry modification
| | Propagation | Mapped network drives |
|
Description:
Files
It copies itself to the following location:
•
%drive%:\ctfmonn.exe
The following files are created:
–
%drive%:\autorun.inf This is a non malicious text file with the following content:
•
%code that runs malware% Registry
The following registry key is added in order to run the process after reboot:
– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
• cftmonn = %SYSDIR%\cftmonn.exe
Miscellaneous
String: Furthermore it contains the following string:
• Vive Avril !!!!!(Tsy virus zany ty!!! lol lol lol