TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_DELF.BRF
Overview

Malware type: Worm

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Medium

Infection Channel 1 : Propagates via removable drives


Description: 

Upon execution, this worm drops a copy of itself as WINCFGS.EXE in the Windows system folder. It also drops and executes the Chinese version of NOTEPAD.EXE, KB20060111.EXE, in the Windows folder.

Whenever a USB device is plugged onto an affected machine, this worm drops a copy of itself in the following path:

    {USB drive letter}\RECYCLER\RECYCLER\autorun.exe

If the path, {USB drive letter}\RECYCLER\RECYCLER does not exist, this worm creates it.

This worm also creates the file {USB drive letter}\AUTORUN.INF, which is responsible in automatically executing AUTORUN.EXE whenever a USB device is plugged on the affected machine.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 29, 2006 4:06:47 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.