This is a new worm that attacks any version of Windows. The worm spreads itself by attaching to any type of fixed or removable hard drive, A-Z.
If you are infected, the worm will create the following files:
C:\lo.tmp
%SYSTEM%\wuauclt.exe
%SYSTEM%\dllcache\wuauclt.exe
%SYSTEM%\wsotdet.dll
%SYSTEM%\wssndet.dll
It will also drop autorun files on drives that it infects.
The worm also edits the Windows Registry so that it will startup every time Windows starts. The registry key affected by this worm is:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\”explorer” = “%System%\wuauclt.exe”
The worm will also attempt to stop various security software and delete their processes. So infected you may become very vulnerable.
Run a scan now:





