This worm may be downloaded from remote sites by other malware. It may be dropped by other malware. It may also be downloaded unknowingly by a user when visiting malicious Web sites.
Upon execution, this worm drops several files, some of which are detected as TROJ_AGENT.AFCK. It injects a dropped .DLL component into several processes running in memory. This worm then creates a registry entry to enable its automatic execution at every system startup. This worm deletes itself after execution.
It modifies registry entries to hide files with both System and Read-only attributes.
This worm drops copies of itself in all physical and removable drives. It also drops an AUTORUN.INF file to automatically execute its dropped copies when the said drives are accessed.
- Add new comment
- Read original article.
- Reset vote
- 3 points