Description:
Upon execution, this worm drops a copy of itself as WINCFGS.EXE in the Windows system folder. It also drops and executes the Chinese version of NOTEPAD.EXE, KB20060111.EXE, in the Windows folder.
Whenever a USB device is plugged onto an affected machine, this worm drops a copy of itself in the following path:
{USB drive letter}\RECYCLER\RECYCLER\autorun.exe
If the path, {USB drive letter}\RECYCLER\RECYCLER does not exist, this worm creates it.
This worm also creates the file {USB drive letter}\AUTORUN.INF, which is responsible in automatically executing AUTORUN.EXE whenever a USB device is plugged on the affected machine.
For additional information about this threat, see: Solution Technical Details
Description created: Jun. 29, 2006 4:06:47 AM GMT -0800
Search a new malware
Tell us how we did. Take our quick survey.
|