Threat Search: 

ThreatExpert's Statistics for W32/Autorun-WT [Sophos]:

W32/Autorun-WT [Sophos] is also known as:
Threat AliasNumber of Incidents
Virus.Win32.PePatch [Ikarus]13
Trojan-Dropper.Win32.VB.iuj [Kaspersky Lab]8
VirTool:Win32/VBInject.S [Microsoft]7
Packed.Win32.VBCrypt.i [Kaspersky Lab]4
Trojan:Win32/Meredrop [Microsoft]4
Generic Dropper [McAfee]3
IRC.Backdoor.Trojan [Symantec]1
Suspicious.MH690 [Symantec]1
VirTool:Win32/VBInject.R [Microsoft]1

W32/Autorun-WT [Sophos] is known to be created as:
%System%\oembios.exe
%Temp%\ixp000.tmp\fada.exe
%Windir%\fxstaller.exe
c:\recycler\k-1-3542-4232123213-7676767-8888886\r00t.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.