Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2008 (4.31) |
| Protection available since | 11 May 2008 13:13:11 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Autorun-DW is a worm which spreads by copying itself to removable devices as the file setup.exe.
W32/Autorun-DW copies itself to <System>\svchost32.exe and creates the following registry entry to run itself on restart:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MyApp
<System>\SVCHOST32.EXE
The worm also creates the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion
MyDate
09-Aug-08
