Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | June 2008 (4.30) |
| Protection available since | 17 April 2008 06:55:38 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/AutoRun-DG is a worm for the Windows platform.
When run, the worm creates the files:
<System>\fool<random number>.dll
<System>\ieso<random number>.dll
<Temp>\<random characters>.dll
<Temp>\<random characters>.sys
These 4 files are also detected as W32/AutoRun-DG.
W32/AutoRun-DG spreads via removable drives by creating the file <Root>\autorun.inf (detected as W32/AutoRun-DG) and copying the worm to <Root>\n2.bat. The autorun.inf is designed to run the worm when the drive is connected to an uninfected computer.
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0
Registry entries are created under:
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\
(default)
IEHlprObj Class
