W32/AutoRun-XF is a worm for the Windows platform.

When run W32/AutoRun-XF copies itself to System\uret463.exe and creates the file System\lhgjyit0.dll (also detected as W32/AutoRun-XF)

W32/AutoRun-XF spreads via removable shared drives by copying itself as Root\6o0.bat and creating the file Root\autorun.inf (also detected as W32/AutoRun-XF).

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dorfgwe
System\uret463.exe

More information can be found at this Sophos page.