W32/Malas-D is a worm for the Windows platform.
When first run W32/Malas-D copies itself to:
Startup\AdobeUpdate.exe
Temp\svchost.exe
User\userinit.exe
Common Files\Microsoft Shared\MSshare.exe
Program Files\XPCode\SexGame.exe
Program Files\XPCode\SexGameList.pif
Program Files\XPCode\SexScreenSaver.scr
Root\autoply.exe
and creates the following files:
Root\Autorun.inf
Startup\Office Update.lnk
Program Files\XPCode\Games.lnk
Windows\Tasks\At1.job
The file Autorun.if is detected as Mal/AutoInf-A, the other files can simply be deleted.
More information can be found at this Sophos page.
Loading Comments...