Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 23 April 2008 04:01:13 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
When first run W32/Autorun-DM copies itself to:
<System>\kaspersky.exe
and creates the following file:
<System>\winlog.txt - 0 byte file, can be deleted safely.
W32/Autorun-DM also copies itself to removable drives with an autorun.inf file to start itself.
W32/Autorun-DM creates registry trees under:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_KSD2SERVICE
HKLM\SYSTEM\CurrentControlSet\Services\KSD2Service
