Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:DR/Autoit.JQ.22
Date discovered:13/01/2009
Type:Dropper
In the wild:Yes
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
Static file:Yes
File size:338.996 Bytes
IVDF version:7.01.01.111 - Tuesday, January 13, 2009

 General Aliases:
   •  Symantec: W32.Harakit
   •  Mcafee: W32/Autorun.worm.cj
   •  Sophos: W32/Autorun-ZW
   •  Panda: W32/Autoit.AB
   •  Grisoft: Worm/Autoit.IZJ
   •  Eset: Win32/Tifaut.C


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Drops a malicious file

 Files It deletes the initially executed copy of itself.



The following file is created:

%TEMPDIR%\s.cmd Furthermore it gets executed after it was fully created. This batch file is used to delete a file.



It tries to executes the following file:

Filename:
   • %TEMPDIR%\s.cmd
This batch file is used to delete a file.

 Miscellaneous Anti debugging
If it was successful it displays the following and terminates immediately:


Description inserted by Petre Galan on Friday, July 3, 2009
Description updated by Petre Galan on Friday, July 3, 2009

Back . . . .