Home / malware Worm:Win32/Autorun.JQ!inf
First posted on 01 October 2012.
Source: MicrosoftAliases :
Worm:Win32/Autorun.JQ!inf is also known as Trojan.Win32.AutoRun.ayj (Kaspersky), W32/Autorun-EW (Sophos), Win32/AutoRun.NAE (ESET), TR/Autorun.113 (Avira), Trojan.Autorun.YV (BitDefender), Win32.HLLW.Autoruner.1548 (Dr.Web).
Explanation :
Worm:Win32/Autorun.JQ!inf is an "autorun.inf" file created by Worm:Win32/Autorun.JQ and Worm:Win32/Autorun.CH in order for the worm to spread and infect other computers through network shares or removable devices.
Such files contain execution instructions for the operating system, so that when the removable drive is accessed from another computer supporting the Autorun feature, the worm is launched automatically.
It should be noted that "autorun.inf" files on their own are not necessarily a sign of infection, as they are used by legitimate programs and installation media.
The worm also copies the "autorun.inf" file into the root of every drive which is accessible on the computer.
Related encyclopedia entries
Worm:Win32/Autorun.JQ
Worm:Win32/Autorun.CH
Analysis by Daniel Chipiristeanu
Last update 01 October 2012