W32/AutoRun-XF is a worm for the Windows platform.
When run W32/AutoRun-XF copies itself to System\uret463.exe and creates the file System\lhgjyit0.dll (also detected as W32/AutoRun-XF)
W32/AutoRun-XF spreads via removable shared drives by copying itself as Root\6o0.bat and creating the file Root\autorun.inf (also detected as W32/AutoRun-XF).
The following registry entry is set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dorfgwe
System\uret463.exe
More information can be found at this Sophos page.
Loading Comments...