VIRUS-W32/Stemclover Worm

W32/Stemclover is a worm. The worm will infect Windows systems and spreads through removable drives and Network drives.

The worm will arrive as a dropped file from the shared folder or mapped drive or removable drive.

Upon execution, the worm copies itself as aniee.com and hanny.exe in the System folder.

The worm modifies registry at the following location to load itself during each startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

It also copies winsys.exe, autorun.inf and Dokter Cinta.Jpg.exe in the removable drives.

The worm is capable of disabling some security related applications.

This worm first appeared on October 09, 2007.