W32/AutoRun-AAT is a worm for the Windows platform.
When run W32/AutoRun-AAT copies itself to System\ierdfgh.exe and creates the file System\pytdfse0.dll (also detected as pytdfse0.dll).
The following registry entry is set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
kxswsoft
System\ierdfgh.exe
W32/AutoRun-AAT spreads via removable shared drives.
More information can be found at this Sophos page.
Loading Comments...