Home / malwarePDF  

Trojan.Autorun.US


First posted on 21 November 2011.
Source: BitDefender

Aliases :

Trojan.Autorun.US is also known as Worm.Win32.VB.fi, Win32.HLLW.Unjap, Worm/VB.FI.5, W32.SillyDC.

Explanation :

This is an autorun.inf file created by different trojans and it is used as an alternative/complementary solution to autorun keys for the malware to ensure it's execution.

They are placed in the root directory of fixed and removable drives and contain the information needed to execute the worm upon access of those drives on systems that have autorun enabled. These kind of files are also used in the spreading process of some worms that copy themselves and create a corresponding autorun.inf file on removable drives like pen drives thus getting executed on other systems on which the infected removable drive will be used.

The file is just a starting point for malware, it does not contain other malicious code.

Last update 21 November 2011

 

TOP