Microsoft security software detects and removes this threat.

This threat is detected by the Microsoft antivirus engine. Technical details are not currently available.

The Win32/Autorun family description has more details.

What to do now

The following Microsoft security software detects and removes this threat: 

Even if we've already detected and removed this particular threat, running a full scan might find other malware that is hiding on your PC

Recovering from recurring infections on a network

You might need to take the following steps to completely remove this threat from an infected network, and to stop recurring infections from network-spreading malware:

  1. Ensure that an antivirus product is installed on all computers connected to the network that can access or host shares.
  2. Ensure that all available network shares are scanned with an up-to-date antivirus product.
  3. Restrict permissions as appropriate for network shares on your network. See Use Access Control to restrict who can use filesfor more information.
  4. Remove any unnecessary network shares or mapped drives.

You might also need to temporarily change the permission on network shares to read-only until the disinfection process is complete.

Threat behavior

The Win32/Autorun family description has more details.


Alerts from your security software may be the only symptom.


This threat tries to use the Windows Autorun function to spread via removable drives, like USB flash drives. You can disable Autorun to prevent worms from spreading: 

Take these steps to help prevent infection on your computer.

Alert level: Severe
First detected by definition:
Latest detected by definition: 1.173.2181.0 and higher
First detected on: Oct 07, 2008
This entry was first published on: Apr 03, 2008
This entry was updated on: Oct 10, 2013

This threat is also detected as:
No known aliases