Sophos

W32/Gmin-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2007 (4.24)
Protection available since 18 October 2007 09:51:04 (GMT)
Detected by All Sophos products

Action

More Information

W32/Gmin-A is a worm for the Windows platform.

When run W32/Gmin-A creates the following files:

<Root>\autorun.inf - detected as W32/Gmin-A
<System>\istart.bat - can be safely removed
<System>\pslist.exe - can be safely removed
<System>\xmreg.reg - can be safely removed
<System>\xm.txt - can be safely removed
<System>\xmhold.bat - detected as W32/Gmin-A
<System>\xuming.bat - detected as W32/Gmin-A
<System>\xuming1.vbs - detected as W32/Gmin-A

W32/Gmin-A spreads via removable shared drives and creates the file <Root>\autorun.inf (also detected as W32/Gmin-A) and copies itself as <Root>\xuming.exe.

The following registry entries are set to run the worm on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
xmstart
xuming.exe

The following registry entries are created set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN
Text

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
Type
radio2

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer