W32/AutoRun-AFV is a worm for the Windows platform.
W32/AutoRun-AFV includes functionality to access the internet and communicate with a remote server via HTTP.
W32/AutoRun-AFV copies itself to removable drives.
When first run W32/AutoRun-AFV copies itself to <System>\uret463.exe and creates the following files:
<System>\drivers\klif.sys
<System>\lhgjyit0.dll
The file klif.sys is detected as Troj/Klif-Gen.
The following registry entry is created to run uret463.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dorfgwe
<System>\uret463.exe