W32/AutoRun-AYG is a worm for the Windows platform.
When run W32/AutoRun-AYG spreads via removable shared drives by creating the following files:
<Root>\autorun.inf (detected as W32/AutoRun-AYG)
<Root>\autorun.vbs (detected as W32/AutoRun-AYG)
<Root>\autorun.bat (detected as W32/AutoRun-AYG)
and copying itself to:
<Documents and Settings>\<User>\Application Data\mplf\mstime32.exe
The following registry entries are set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Intel Management Services v32
<Documents and Settings>\<User>\Application Data\mplf\mstime32.exe