Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2007 (4.24) |
| Protection available since | 18 October 2007 09:51:04 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Gmin-A is a worm for the Windows platform.
When run W32/Gmin-A creates the following files:
<Root>\autorun.inf - detected as W32/Gmin-A
<System>\istart.bat - can be safely removed
<System>\pslist.exe - can be safely removed
<System>\xmreg.reg - can be safely removed
<System>\xm.txt - can be safely removed
<System>\xmhold.bat - detected as W32/Gmin-A
<System>\xuming.bat - detected as W32/Gmin-A
<System>\xuming1.vbs - detected as W32/Gmin-A
W32/Gmin-A spreads via removable shared drives and creates the file <Root>\autorun.inf (also detected as W32/Gmin-A) and copies itself as <Root>\xuming.exe.
The following registry entries are set to run the worm on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
xmstart
xuming.exe
The following registry entries are created set:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN
Text
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
Type
radio2
