Runtime behavior alerts of this type inform the user that a hidden autorun file has been opened for writing in a temporary or sensitive/protected location on the file system. Any attempt at this behavior by an unauthorized program could indicate a malware infection.
Please note that the behavior of some legitimate product installers can sometimes resemble that of malware. For this reason, installing or updating software carries an increased likelihood of unwanted HIPS detections and we recommend configuring HIPS to Alert Only mode for the duration of any product installs or updates. For further information please refer to the following knowledgebase article deciding whether to allow or block a file.
HIPS/FileWriteMod-006 uses Sophos Behavioral Genotype technology to enhance detection accuracy.