Sophos

Sophos blogs

W32/Autorun-AUH

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 6 November 2009 21:40:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Autorun-AUH is a worm for the Windows platform.

W32/Autorun-AUH includes functionality to:

- create batch scripts in the <WINDOWS> folder
- run automatically
- copy itself to the <WINDOWS>\system32 folder
- create files in the <WINDOWS>\system32 folder

When W32/Autorun-AUH is installed the following files are created:

<System>\Se813.exe
<System>\_Se813.exe
<Root>\AutoRun.inf (this file is detected as Mal/AutoInf-A)
<Root>\Se813.exe

The worm may create registry entries under:

HKLM\System\CurrentControlSet\Services,Windows_rejoice2007_813\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer