Sophos

W32/AutoRun-GJ

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Included in our products from September 2008 (4.33)
Protection available since 16 July 2008 19:05:13 (GMT)
Detected by All Sophos products

Action

More Information

W32/AutoRun-GJ is a worm with IRC backdoor functionality for the Windows platform.

W32/AutoRun-GJ runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When first run W32/AutoRun-GJ copies itself to <Root>\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\usb32.exe.

W32/AutoRun-GJ copies itself to any removable drives and the file autorun.inf, detected as Mal/AutoInf-A, is created to run this file.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer