Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jan 24, 2011 | Updated Sep 15, 2017

Worm:Win32/Autorun.AAY

Detected by Microsoft Defender Antivirus

Aliases: Mal/FakeAV-FS (Sophos) TROJ_RAMNIT.R (Trend Micro) Troj/Zbot-ADH (Sophos) W32.Ramnit.B (Symantec)

Summary

Worm:Win32/Autorun.AAY is a worm that spreads by copying itself to removable and network drives. The worm attempts to connect to a remote server via TCP port 443.
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
Follow us