Selected viruses, spyware, and other threats: sorted alphabetically
Short descriptionWin32/AutoRun.Delf.HH is a worm that spreads via removable media. The worm can download and execute a file from the Internet.
InstallationWhen executed, the worm copies itself into the following location:
- %windir%SysRegSrvc.exe (558080 B)
"MSkip" = "%windir%SysRegSrvc.exe"
"SuperHidden" = 0
"ShowSuperHidden" = 0
Spreading on removable mediaThe worm copies itself into the root folders of removable drives using the following filename:
Information stealingThe worm collects the following information:
- computer name
- user name
- CPU information
Other informationThe worm restarts the operating system if there is a window with any of the following strings in the name:
- The Wireshark Network Analyzer
The worm contains a list of (2) URLs. The HTTP protocol is used.
The worm can download and execute a file from the Internet.