W32/AutoRun-DG is a worm for the Windows platform.

When run, the worm creates the files:

System\fool(random number).dll
System\ieso(random number).dll
Temp\(random characters).dll
Temp\(random characters).sys


These 4 files are also detected as W32/AutoRun-DG.

W32/AutoRun-DG spreads via removable drives by creating the file Root\autorun.inf (detected as W32/AutoRun-DG) and copying the worm to Root\n2.bat. The autorun.inf is designed to run the worm when the drive is connected to an uninfected computer.

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Hidden
2

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0

Registry entries are created under:

HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\
(default)
IEHlprObj Class

More information can be found at this Sophos page.