Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 24 April 2008 01:55:53 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
When first run W32/Autorun-DP copies itself to:
- <Windows>\windowsmp.exe
- <System>\init.exe
- <Windows>\yoos.b
- <Root>\explorer.exe
The following registry entry is created to run windowsmp.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
windowsmp
<Windows>\windowsmp.exe
