W32/Autorun-AUI is a Trojan for the Windows platform.
W32/Autorun-AUI includes functionality to:
- run automatically
- steal confidential information
- disable other software, including anti-virus, firewall and security related applications
When W32/Autorun-AUI is installed the following files are created:
<Temp>\cvasds0.dll (detected as Mal/Generic-A)
<Temp>\herss.exe (copy of the worm)
The following registry entry is created to run herss.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
cdoosoft
<Temp>\herss.exe