INF_OTORUN.VBFS
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It automatically executes files when a user opens a drive.
TECHNICAL DETAILS
INF
04 Feb 2013
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Propagation
The said .INF file contains the following strings:
{garbage characters}
[autorun]
{garbage characters}
open={random}.EXE
{garbage characters}
ActIoN={random number}
{garbage characters}
uSeautoplay=1
{garbage characters}
Other Details
This Trojan automatically executes the following files when a user opens a drive:
- {drive letter}:\{random file name}.exe