Sophos

W32/Autorun-CL

Aliases
  • Worm.Win32.AutoRun.dao
  • W32.Gammima.AG
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Included in our products from April 2008 (4.29)
Protection available since 25 March 2008 22:02:24 (GMT)
Detected by All Sophos products

Action

More Information

W32/Autorun-CL is a worm for the Windows platform.

When first run W32/Autorun-CL copies itself to <System>\amvo.exe and creates the following files:

<Temp>\9ht.dll - detected as W32/Autorun-CL
<Temp>\g1.sys - detected as W32/Autorun-CL
<System>\amvo0.dll - proactively detected as Mal/Behav-204

The following registry entry is created to run amvo.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
amva
<System>\amvo.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer