Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | April 2008 (4.29) |
| Protection available since | 24 March 2008 10:10:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Autorun-CH is a worm for the Windows platform.
When first run W32/Autorun-CH copies itself to the User folder and creates the following files:
<User>\Application Data\tr2.bmp
<Temp>\aut1.tmp
The following registry entry is set:
HKCU\Control Panel\desktop
wallpaper
<User>\Application Data\tr2.bmp
W32/Autorun-CH spreads by copying itself to removable media as <drive>\explorer.exe. To run this file, <drive>\autorun.inf is also created.
