Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 28 March 2009 13:44:43 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/AutoRun-ADI is a worm for the Windows platform.
When run W32/AutoRun-ADI copies itself to <System>\acroread.exe and creates the files:
<System>\vb6stkit.dll - this file can be safely removed
C:\drive.inf - this file can be safely removed
W32/AutoRun-ADI also attempts to terminate Windows System services such as LSASS.EXE.
W32/AutoRun-ADI sets the following registry entries under:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

