If you havn't already downloaded this bot, don't, i know what you must be thinking, Runescape is for kids, blah blah, but it does contain a virus, my firewall, (Pctools) blocked Au_.exe, it was located in my local temp folder, if you don't know what Au_.exe is:
The Au_.exe executable file belongs to the rogue anti-spyware program, SpyFalcon. This malicious program camouflages itself as an anti-spyware utility when in fact it is a Trojan. This malware has the capability to infiltrate your computer through security exploits and install itself along with other Trojans. What the file basically does is hijack the user’s desktop and changes user settings to make it function according to its own requirements.
Au_.exe is also linked to many other spyware, adware and cloaked malware groups. Where some say that the origin of this Trojan is unknown, some are of the opinion that the malicious software to which the file belongs can be downloaded easily from manufacturer’s website. The file is also said to be a part of the Arovax Anti-Spyware software. This may be probable, as the initial description says that this executable pretends to be an anti-spyware application.
How Au_.exe Infects your PC
The following are some of the ways au_.exe is known to affect the PC it infects:
Deletes essential processes from the disk
Executing harmful processes stored in temporary folders
Creates other potentially dangerous processes on your system.
Uses HTTP protocols to communicate with other computer systems for malicious purposes.
Adds bad entries to the registry.
Hijacks system processes to delete links in the Start Menu and can be a source of annoyance for many users.
Looks at what’s inside the autoexec.bat file and invades your privacy by reading email addresses and phone book details.
IF you have downloaded this bot, and you are seeing decreases in PC performance, files disappearing, or anything else strange, open task manager, go to processes, Select: Show processes from all users, look for Au_.exe, and end it, then go to: C:\Users\User\AppData\Local\Temp, if you see a folder ~nsu.tmp open it, and see if there is a program with the Epicbot icon, if so, go back and delete the ~nsu.tmp and restart your computer.