|W32.Mafeg is a memory-resident, file-appending worm that attempts to spread itself through shared network resources.
When W32.Mafeg does the following:
Inserts the Dxupdate.exe file to the %System% folder.
Adds the value:
to the registry key:
If the system is Windows NT/2000/XP/Server 2003, it will attempt to infect the C:\NTLDR file.
Displays a message box in Chinese, if the year of the system date is greater than 2003 and the day of the week is Saturday.
Use antivirus (also check How To Remove section)Start Control to automatically remove it from Startup.