AutoIt.D may arrive on the system as a downloaded file via links that are spammed through Yahoo Messenger.
It may use any of the following message strings:
• A new dangerous computer virus that can destroys all your data has just been
released . Click here to know how to avoid it :
http://www.geocities.co.jp/ie_[REMOVED] <<
• Cac ban co the tranh bi nhiem cac loai virus online gan day bang cach update
Windows . Vao day de biet cach Update Win ma ko can ban quyen Windows xin:
http://www.geocities.co.jp/ie_[REMOVED]
• cai dit con me may day . Lua tao a` ? Xem di :
http://www.geocities.co.jp/tha[REMOVED] X-(
• cool girls : http://www.geocities.co.jp/tha[REMOVED] :x:x:x:x:x
• di'nh virus ru`i =)) du`ng cai nay ma diet na`y :
http://www.geocities.co.jp/ie_[REMOVED]
• Download free MP3s : http://www.geocities.co.jp/tha[REMOVED] <<
• ha`i dek chiu dc =)) http://www.geocities.co.jp/tha[REMOVED] =)) =))
• have you ever seen such a silly man like this ?
http://www.geocities.co.jp/tha[REMOVED] =))
• Just check out my new personal website :
http://www.geocities.co.jp/tha[REMOVED] C00l !!!
• Let's vote for Miss Vietnam - Mai Phuong Thuy - for the upcoming
Miss World championship : http://www.geocities.co.jp/tha[REMOVED] !!
• making money online never be easier :
http://www.geocities.co.jp/tha[REMOVED] >:D<
• Now you can avoid some critical online viruses by updating Windows .
Click here to know how to Update your Windows :
http://www.geocities.co.jp/tha[REMOVED]
• the only way to clean some online viruses that may lead you into troubles :
http://www.geocities.co.jp/ie_[REMOVED] <<
• Use this tool to remove the viruses from your PC :
http://www.geocities.co.jp/ie_[REMOVED] <<
• wtf is this ? Wanna give me a shit ?
http://www.geocities.co.jp/tha[REMOVED] X-( <<
This is done by searching for the string title "Yahoo! Messenger" in the Windows Title Bar. When the string found, AutoIt.D will secretly and randomly input any of the above messages, every 80 seconds.
The links in the messages direct to script pages that may contain any of the following download sites:
• http://my.opera.com/termex18388/homes/files/[REMOVED].exe
• http://www.geocities.co.jp/thanatos18388/[REMOVED].jpg
Below is a sample message:

Upon execution, this malware attempts to download another malware file from the following site:
• http://www.geocities.co.jp/thanatos18388/[removed].jpg
The downloaded file is saved and executed on the victim's machine with the following filename:
This file is detected as IM-Worm.Win32.Sohanad.b.
To enable its automatic execution on startup, it creates the following registry launch point:
• [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
Task Manager ="%WinDir%\svchost32.exe"
AutoIt.D also changes the Internet Home Page, Yahoo Buzz and Yahoo Launchcast links to the following site:
• http://www.geocities.co.jp/th[REMOVED]
It locks the home page in Internet Explorer by modifying the following registry entry:
• [HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel]
Homepage="1"
Note: The value of Homepage varies between users. Homepage="0" will unlock the homepage settings.
It also disables Task Manager and Registry Editor by creating the following registry entries:
• [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
DisableTaskMgr="1"
• [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
DisableRegistryTools="1"
AutoIt.D is actually a script file converted to an executable file using AutoIt.