Trojan.Vb.AQT
* a "Recycled" folder on each drive, which has the icon of the Recycle Bin
* presence of a file "autorun.inf" in the drive root, containing:[autorun]
shellexecute=Recycled\Recycled\ctfmon.exe
shell\Open(O)\command=Recycled\Recycled\ctfmon.exe
shell=Open(0)
[DRIVE]:\autorun.inf, which are used to execute the malware when the drive is accessed.
[DRIVE]:\Recycled\desktop.ini
[DRIVE]:\Recycled\INFO2,
[DRIVE]:\Recycled\Recycled\ctfmon.exeCreates the following files as to be executed on Windows startup:
%User%\Start Menu\Programs\Startup\desktop.ini
%User%\Start Menu\Programs\Startup\ctfmon.exe
SHARE
THIS ON