VBS/Autorun.worm.zy is a generic detection for worms that propagates itself on the root of all drives on the infected computer. VBS/Autorun.worm.zy uses an Autorun.inf file so that the worm is loaded each time the volume is mounted.

Aliases:
-

Risk Level: Low

File Size: 1,544 bytes

Affected System: Windows

Common Symptoms:
1. Presence of registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeCaption: “Codename:Lavos”

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\Current Version\Winlogon\LegalNoticeText: “Your Computer Has Been Infected”

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon\Shell: “Explorer.exe wscript.exe %WinDir\system32\lavos.vbs”