We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Autorun.ZZ
Detected by Microsoft Defender Antivirus
Aliases: TR/Agent.eige (Avira) Win32.HLLW.Autoruner.26463 (Dr.Web) Win32/AutoRun.Agent.XK (ESET) W32/Autorun.worm.bbj (McAfee) Troj/Agent-OVO (Sophos)
Summary
Worm:Win32/Autorun.ZZ is a worm that spreads by copying itself to mapped network drives as a file named "klickmich1000.exe". The worm attempts to communicate with the remote server "lysclassic.dyndns.org".
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.