| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed | 261509 |
| N/A | |
| 3195b1db171dbb9a2fcf2012d9a5ff03 | |
| 214553ca646da187bd999fb308de14510ca3ef37 | |
| 73a76ccc66636793143d7ee24191e3dc6a5a28b69815d963098fdf9ca999f899 | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| 255 kB | |
| Intel 386 or later, and compatibles | |
| Win32 | |
| 225280 | |
| 4.0 | |
| 0x98190 | |
| 0x0017 | |
| 8.0 | |
| N/A | |
| 397312 | |
| 28672 | |
| N/A | |
| 3.2.8.1 | |
| application/octet-stream | |
| Unicode | |
| English (British) | |
| 3.2.8.1 | |
| Win32 EXE | |
| ., ., ., . | |
| Windows GUI | |
| Unknown | |
| 0.0 | |
| (none) | |
| 4.0 | |
| Source: |

| AVG | Worm/Autoit.ATK |
| AhnLab-V3 | Win32/Hybris.worm.261572 |
| AntiVir | TR/Crypt.CFI.Gen |
| Authentium | W32/Worm.MWD |
| Avast | Win32:AutoRun-SF |
| BitDefender | Win32.Worm.AutoIt.Z |
| CAT-QuickHeal | Worm.AutoIt.r |
| ClamAV | Trojan.KillAV-235 |
| Comodo | Worm.Win32.AutoIt.~AN |
| DrWeb | Win32.HLLW.Texmer.49 |
| F-Prot | W32/Worm.MWD |
| F-Secure | Worm.Win32.AutoIt.r |
| Fortinet | W32/Agent.ALS!tr |
| GData | Win32.Worm.AutoIt.Z |
| Ikarus | Worm.Win32.AutoIt |
| K7AntiVirus | Worm.Win32.AutoRun |
| Kaspersky | Worm.Win32.AutoIt.r |
| McAfee | W32/YahLover.worm |
| McAfee+Artemis | W32/YahLover.worm |
| McAfee-GW-Edition | Trojan.Crypt.CFI.Gen |
| Microsoft | Worm:Win32/Yuner.A |
| NOD32 | Win32/Yuner.B |
| NOD32Beta | Win32/Yuner.B |
| PCTools | Worm.Agent.EOVV |
| Prevx1 | High Risk Worm |
| Sophos | W32/Yuner-A |
| Symantec | W32.Badday.A |
| TheHacker | W32/AutoRun.cbd |
| TrendMicro | WORM_UTOTI.BU |
| VBA32 | Worm.Win32.AutoRun.cby |
| ViRobot | Worm.Win32.AutoIt.261440 |
| VirusBuster | Worm.Agent.EOVV |
| a-squared | Worm.Win32.AutoIt!IK |
| eSafe | Suspicious File |
| nProtect | Worm/W32.AutoIt.261509 |