Home / malwarePDF  

Worm:INF/Autorun.B


First posted on 22 May 2012.
Source: Microsoft

Aliases :

Worm:INF/Autorun.B is also known as Worm.Win32.VB.fi (Kaspersky), Worm.AutoRun.AM (VirusBuster), Worm/AutoRun (AVG), TR/Autorun.EV (Avira), INF/Autorun virus (ESET).

Explanation :



Worm:INF/Autorun.B is the detection for files with the name "autorun.inf" that may be used by worms when spreading to local, network, or removable drives. When copying themselves to a drive, worms can create a file named "autorun.inf" that contains instructions for the operating system. When the drive is viewed using Windows Explorer, "autorun.inf" may automatically run, thus running the worm copy.

It should be noted that "autorun.inf" files on their own are not necessarily a sign of infection, as they are used by legitimate programs and installation CDs.

Files detected as Worm:INF/Autorun.B are known to be created by malware detected as Worm:Win32/Fakerecy.B.



Analysis by Jaime Wong

Last update 22 May 2012

 

TOP