W32/Autorun-AUD

Category: Viruses and Spyware Protection available since:03 Nov 2009 23:29:05 (GMT)
Type: Win32 worm Last Updated:03 Nov 2009 23:29:05 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Autorun-AUD spreads via removable storage devices.

When W32/Autorun-AUD is run, it copies itself to <User>\lsass.exe.

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LSA Shellu
<User>\lsass.exe

download Try Sophos products for free
Download now