Selected viruses, spyware, and other threats: sorted alphabetically
Short descriptionWin32/AutoRun.Delf.CB is a worm that spreads by copying itself into the root folders of available drives.
InstallationWhen executed the worm copies itself in the following locations:
In order to be executed on every system start, the worm sets the following Registry entry:
The following Registry entries are created:
"sdll32" = "%windir%\Help\svcnost.exe"
The following Registry entries are set:
"ShowSuperHidden" = 0
"NoFolderOptions" = 1
"NoFind" = 1
"NoRun" = 1
- [HKEY_CURRENT_USER\Control Panel\Desktop]
"ScreenSaveTimeOut" = 2
"SCRNSAVE.EXE" = "%system%\ssmarque.scr"
- [HKEY_CURRENT_USER\Control Panel\Screen Saver.Marquee]
SpreadingWin32/AutoRun.Delf.CB is a worm that spreads by copying itself into the root folders of available drives.
The following filenames are used:
The following file is dropped in the same folder:
- MY DOCUMENTS.exe
Thus, the worm ensures it is started each time infected media is inserted into the computer.
Other informationThe worm displays the following dialog box:
The worm may open the CD/DVD drive.
The worm creates the following files: