autorun.inf – worm Autorun
Alex NightWatcher: Solved! Fix it immediately: The file C:\AutoRun.inf is a computer worm. The worm C:\AutoRun.inf is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the C:\AutoRun.inf problem as soon as possible! Delete the file C:\AutoRun.inf from all infected computers in your network. [...]
Removed: C:\AutoRun.inf, C:\WINDOWS\winxp_32.exe (rootkit – backdoor Hupigon)
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\winxp_32.exe Removed: C:\AutoRun.inf C:\WINDOWS\winxp_32.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: C:\autorun.inf Author: Unknown Related File: C:\autorun.inf Type: Autorun.inf Item Name: World Wide Web Publishing Service Author: Related File: C:\WINDOWS\winxp_32.exe Type: Auto Services After first reboot detected by UnHackMe: Item Name: World Wide Web Publishing Service Author: Related File: [...]
Removed: ahnabc.exe, ahnabc0.dll, ahnie0.dll, hgking.exe, hgking0.dll, kingie0.dll, autorun.inf, di69.exe, ivc6yd.exe (trojan Frethog)
Alex NightWatcher: Solved! Fix it immediately: Malware: 1ahnabc.exe Removed: C:\WINDOWS\system32\ahnabc.exe C:\WINDOWS\system32\ahnabc0.dll C:\WINDOWS\system32\ahnie0.dll C:\WINDOWS\system32\hgking.exe C:\WINDOWS\system32\hgking0.dll C:\WINDOWS\system32\kingie0.dll C:\autorun.inf C:\di69.exe C:\ivc6yd.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: {70F6E582-8FF4-4082-829E-C172131DE31A} Author: Related File: C:\WINDOWS\SYSTEM32\AHNIE0.DLL Type: Browser Helper Objects Item Name: ahnabc.exe Author: Unknown Related File: C:\WINDOWS\SYSTEM32\AHNABC.EXE Type: Detected using Heuristic Algorithm Item Name: ahnabc0.dll Author: Unknown Related File: C:\WINDOWS\SYSTEM32\AHNABC0.DLL Type: [...]
Removed: C:\WINDOWS\csrss.exe, C:\autorun.inf (VBMania)
Alex NightWatcher: Solved! Fix it immediately: Malware: malware.exe Removed: C:\WINDOWS\csrss.exe C:\autorun.inf —————————————————————————————————————————- Detected by UnHackMe: Item Name: shell Author: Unknown Related File: Explorer.exe C:\WINDOWS\csrss.exe Type: System.ini Item Name: 00hoeav.com Author: Related File: C:\WINDOWS\CSRSS.EXE Type: Image Executions Debugger /…/ Item Name: zonealarm.exe Author: Related File: C:\WINDOWS\CSRSS.EXE Type: Image Executions Debugger Item Name: csrss.exe Author: Related File: [...]
Removed: C:\WINDOWS\system32\ati2avxx.exe, C:\autorun.inf, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\START MENU\PROGRAMS\STARTUP\AOUPBIE.EXE (trojan Mocmex)
Alex NightWatcher: Solved! Fix it immediately: Malware: mlburmh.exe Removed: C:\WINDOWS\system32\ati2avxx.exe C:\autorun.inf C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\START MENU\PROGRAMS\STARTUP\AOUPBIE.EXE —————————————————————————————————————————- Detected by UnHackMe: Item Name: ati2avxx Author: Unknown Related File: C:\WINDOWS\SYSTEM32\ATI2AVXX.EXE Type: Registry Run Item Name: ati2avxx.exe Author: Unknown Related File: C:\WINDOWS\SYSTEM32\ATI2AVXX.EXE Type: Running Processes Item Name: C:\autorun.inf Author: Unknown Related File: C:\autorun.inf Type: Autorun.inf Item Name: aoupbie.exe Author: [...]
Removed: autorun.inf, SAFESYS.EXE, dbsna.fon, ~powom.tmp, hvvus.fon, vpnrv.fon, xmxns.fon, xxnbl.fon, nfewp.fon Restored: C:\WINDOWS\SYSTEM32\SPOOLSV.EXE (trojan Bosbot)
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\SafeSys.exe Removed: C:\autorun.inf C:\PROGRAM FILES\COMMON FILES\SAFESYS.EXE C:\WINDOWS\Fonts\dbsna.fon C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~powom.tmp C:\WINDOWS\Fonts\hvvus.fon C:\WINDOWS\Fonts\vpnrv.fon C:\WINDOWS\Fonts\xmxns.fon C:\WINDOWS\Fonts\xxnbl.fon C:\WINDOWS\Fonts\nfewp.fon Restored: C:\WINDOWS\SYSTEM32\SPOOLSV.EXE —————————————————————————————————————————- Detected by UnHackMe: Item Name: C:\autorun.inf Author: Unknown Related File: C:\autorun.inf Type: Autorun.inf Item Name: SafeSys Author: Unknown Related File: C:\PROGRAM FILES\COMMON FILES\SAFESYS.EXE Type: Registry Run After first reboot detected by UnHackMe: [...]
Removed: scvhost.exe, autorun.inf, extext64750t.exe Restored: C:\WINDOWS\system32\drivers\asyncmac.sys C:\WINDOWS\SYSTEM32\USERINIT.EXE (trojan AntiAV)
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\p.exe Removed: C:\WINDOWS\system32\scvhost.exe C:\autorun.inf C:\WINDOWS\extext64750t.exe Restored: C:\WINDOWS\system32\drivers\asyncmac.sys C:\WINDOWS\SYSTEM32\USERINIT.EXE —————————————————————————————————————————- Detected by UnHackMe: Item Name: scvhost.exe Author: Unknown Related File: C:\WINDOWS\SYSTEM32\SCVHOST.EXE Type: Running Processes Item Name: C:\autorun.inf Author: Unknown Related File: C:\autorun.inf Type: Autorun.inf Item Name: extext64234t.exe Author: Unknown Related File: C:\WINDOWS\EXTEXT64234T.EXE Type: Running Processes After first reboot detected [...]
Removed: AutoRun.inf, re008.exe (backdoor Hupigon)
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\13cmd.exe Removed: C:\AutoRun.inf C:\WINDOWS\system32\re008.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: C:\autorun.inf Author: Unknown Related File: C:\autorun.inf Type: Autorun.inf Item Name: windows Author: Related File: C:\WINDOWS\system32\re008.exe Type: Auto Services Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.16 Backdoor.Hupigon.AYYX Kaspersky 7.0.0.125 [...]
Removed: 6TO4EX.DLL, iejore.exe, autorun.inf, SNOWFALL.EXE, F00030562K.CMD, TencentQQ.exe (trojan Obfuscator)
Alex NightWatcher: Solved! Fix it immediately: Malware: css.exe Removed: C:\WINDOWS\SYSTEM32\6TO4EX.DLL C:\Program Files\Common Files\Microsoft Shared\MSINFO\iejore.exe C:\autorun.inf C:\WINDOWS\SYSTEM32\SNOWFALL.EXE C:\WINDOWS\SYSTEM32\F00030562K.CMD C:\WINDOWS\TencentQQ.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: 6to4 Author: Microsoft Corporation Related File: C:\WINDOWS\SYSTEM32\6TO4EX.DLL Type: Svchost DLLs Item Name: shell Author: Unknown Related File: Explorer.exe C:\Program Files\Common Files\Microsoft Shared\MSINFO\iejore.exe Type: System.ini Item Name: C:\autorun.inf Author: Unknown Related File: [...]
Removed: SafeDrv.exe, autorun.inf, tinlater.exe, Drv.sys (trojan Buzus)
Alex NightWatcher: Solved! Fix it immediately: Malware: 97sese.exe Removed: C:\Program Files\Common Files\SafeDrv.exe C:\autorun.inf C:\WINDOWS\tinlater.exe C:\WINDOWS\system32\drivers\Drv.sys —————————————————————————————————————————- Detected by RegRun Warrior: Item Name: SafeDrv Author: Unknown Related File: C:\PROGRAM FILES\COMMON FILES\SAFEDRV.EXE Type: Explorer Run Item Name: C:\autorun.inf Author: Unknown Related File: C:\autorun.inf Type: Autorun.inf Item Name: Ms-tl_Srv Author: Related File: C:\WINDOWS\tinlater.exe Type: Drivers Item Name: One [...]
Removed: csrcs.exe, ..\SYSTEM32\AUTORUN.INF
Alex NightWatcher: Solved! Fix it immediately: Malware: vvbxua.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\csrcs.exe C:\WINDOWS\SYSTEM32\AUTORUN.INF —————————————————————————————————————————- Detected by UnHackMe: Item Name: shell Author: Unknown Related File: Explorer.exe csrcs.exe Type: System.ini Item Name: csrcs Author: Unknown Related File: C:\WINDOWS\SYSTEM32\CSRCS.EXE Type: Explorer Run Item Name: csrcs.exe Author: Unknown Related File: C:\WINDOWS\SYSTEM32\CSRCS.EXE Type: Detected using Heuristic Algorithm Item Name: autorun.inf Author: [...]
Removed: ZYDXC0209.DLL, autorun.inf, pcidump.sys. Restored: DSOUND.DLL, RPCSS.DLL
Alex NightWatcher: Solved! Fix it immediately: Malware: 030.exe Removed: C:\WINDOWS\SYSTEM32\ZYDXC0209.DLL C:\autorun.inf C:\WINDOWS\SYSTEM32\DRIVERS\pcidump.sys Restored: C:\WINDOWS\SYSTEM32\DSOUND.DLL C:\WINDOWS\SYSTEM32\RPCSS.DLL —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.24 Trojan.Generic.3115629 Kaspersky 7.0.0.125 2010.03.24 Trojan-Downloader.Win32.Geral.noj McAfee 5929 2010.03.23 – Microsoft 1.5605 2010.03.24 TrojanDropper:Win32/Dogkild.A NOD32 4969 2010.03.23 a variant of Win32/AutoRun.KillAV.N —————————————————————————————————————————- Additional information File size: 32256 bytes MD5 : 7810b652c7244875b4d99bd9288aee3c SHA1 : c63bb1a1e90332a6245f5420efc3c653894d36f6 [...]
Removed: autorun.inf, NOOJI.SYS (random filename)
Alex NightWatcher: Solved! Fix it immediately: Malware: d386a7b7eae8219b30716aeac5c03c54.exe Removed: C:\autorun.inf C:\WINDOWS\SYSTEM32\DRIVERS\NOOJI.SYS (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.29 Win32.Sality.N Kaspersky 7.0.0.125 2010.03.29 P2P-Worm.Win32.Bacteraloh.h McAfee 5934 2010.03.28 W32/Sality.gen Microsoft 1.5605 2010.03.28 Virus:Win32/Sality.T NOD32 4980 2010.03.28 Win32/Sality.NAM —————————————————————————————————————————- Additional information File size: 155648 bytes MD5 : bd023ab9eb3fddb7182f3bfbbcdfcafe SHA1 : 9a7364b297841c5883dda227681f321d44fb0b4e SHA256: 97200d75131bda00201ebf0af3978652f3f51d01e7c6d5864028a4e820474c75 [...]
Removed: herss.exe, autorun.inf
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\68b65963ef97b01e534a36a281e6e3c8.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\herss.exe C:\autorun.inf —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.23 Backdoor.Bot.113221 Kaspersky 7.0.0.125 2010.02.23 Trojan-GameThief.Win32.Magania.ctye McAfee 5901 2010.02.23 PWS-Mmorpg!mg Microsoft 1.5406 2010.02.23 PWS:Win32/Frethog.gen!H NOD32 4890 2010.02.23 a variant of Win32/PSW.OnLineGames.OSR —————————————————————————————————————————- Additional information File size: 91648 bytes MD5 : 67fe835d13fa9a019f6eec4f9d20daf3 SHA1 [...]
Removed: autorun.inf, NOOJI.SYS (random filename)
Alex NightWatcher: Solved! Fix it immediately: Malware: d386a7b7eae8219b30716aeac5c03c54.exe Removed: C:\autorun.inf C:\WINDOWS\SYSTEM32\DRIVERS\NOOJI.SYS (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.29 Win32.Sality.N Kaspersky 7.0.0.125 2010.03.29 P2P-Worm.Win32.Bacteraloh.h McAfee 5934 2010.03.28 W32/Sality.gen Microsoft 1.5605 2010.03.28 Virus:Win32/Sality.T NOD32 4980 2010.03.28 Win32/Sality.NAM —————————————————————————————————————————- Additional information File size: 155648 bytes MD5 : bd023ab9eb3fddb7182f3bfbbcdfcafe SHA1 : 9a7364b297841c5883dda227681f321d44fb0b4e SHA256: 97200d75131bda00201ebf0af3978652f3f51d01e7c6d5864028a4e820474c75 [...]
Removed: herss.exe, autorun.inf
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\5131e30e1ebc0f096f17b3528d236362.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\herss.exe C:\autorun.inf —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.26 Trojan.Agent.AORM Kaspersky 7.0.0.125 2010.02.26 Trojan-GameThief.Win32.Magania.cweh McAfee 5903 2010.02.25 Generic PWS.y!bzn Microsoft 1.5502 2010.02.26 PWS:Win32/Frethog.gen!H NOD32 4899 2010.02.26 a variant of Win32/PSW.OnLineGames.OTM Symantec 20091.2.0.41 2010.02.26 Trojan Horse —————————————————————————————————————————- Additional information File size: [...]
Removed: wincab.sys, avpo.exe, avpo0.dll, autorun.inf
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\270fb85defe528119c3de1194253f7ac.exe Removed: C:\windows\system32\wincab.sys C:\WINDOWS\system32\avpo.exe C:\WINDOWS\system32\avpo0.dll C:\autorun.inf —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 8.0.14470.0 2009.04.25 Trojan-GameThief.Win32.OnLineGames.aqu Kaspersky 7.0.0.125 2009.04.26 Trojan-GameThief.Win32.OnLineGames.aqu McAfee 5596 2009.04.25 PWS-Gamania.gen.a Microsoft 1.4602 2009.04.25 TrojanDownloader:Win32/Small.gen!L NOD32 4035 2009.04.25 Win32/Pacex Symantec 1.4.4.12 2009.04.26 Infostealer.Gamania —————————————————————————————————————————- Additional information File size: 67643 bytes MD5 : 548731b9c12664d69b09433388f91141 SHA1 [...]
Removed: autorun.inf
Alex NightWatcher: Solved! Fix it immediately: Malware: malware.exe Removed: C:\autorun.inf —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.22 MemScan:Trojan.Generic.2008016 Kaspersky 7.0.0.125 2010.01.22 Trojan.Win32.Tdss.afwo McAfee 5869 2010.01.22 DNSChanger!o Microsoft 1.5405 2010.01.22 Trojan:Win32/Alureon.BK NOD32 4798 2010.01.22 a variant of Win32/Kryptik.RR Symantec 20091.2.0.41 2010.01.22 Trojan Horse —————————————————————————————————————————- Additional information File size: 93474 bytes MD5 : 980defa4a2f08a52e3ec7d51baa3f393 [...]
Removed: autorun.inf, boot.com
Alex NightWatcher: Solved! Fix it immediately: Malware: malware.exe Removed: C:\autorun.inf(C:\resycled\boot.com) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.20 Trojan.TDss.AU Kaspersky 7.0.0.125 2010.01.20 Trojan.Win32.DNSChanger.uek McAfee 5866 2010.01.19 DNSChanger.gen Microsoft 1.5302 2010.01.20 Trojan:Win32/Alureon.gen!J NOD32 4788 2010.01.20 a variant of Win32/Kryptik.CN Symantec 20091.2.0.41 2010.01.20 Trojan Horse —————————————————————————————————————————- Additional information File size: 80399 bytes MD5 : e9b0140a7d0590cdc49f1219cb13955f [...]
Removed: Recycle.exe, AutoRun.inf, only.exe
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\wow.exe Removed: C:\WINDOWS\Recycle.exe C:\AutoRun.inf C:\WINDOWS\system32\only.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.23 Generic.FWB.3DE47DE8 Kaspersky 7.0.0.125 2010.01.23 Worm.Win32.AutoRun.bms McAfee 5869 2010.01.22 Downloader-BFO Microsoft 1.5405 2010.01.23 Worm:Win32/Autorun.CY NOD32 4798 2010.01.22 a variant of Win32/AutoRun.Delf.P Symantec 20091.2.0.41 2010.01.23 W32.SillyDC —————————————————————————————————————————- Additional information File size: 42478 bytes MD5 : [...]
Removed: autorun.inf
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\malware.exe Removed: C:\autorun.inf —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.20 Worm.Generic.66462 Kaspersky 7.0.0.125 2010.01.20 Trojan.Win32.TDSS.affr McAfee 5866 2010.01.19 FakeAlert-DA Microsoft 1.5302 2010.01.20 Trojan:Win32/Alureon.BK NOD32 4788 2010.01.20 Win32/AutoRun.ABH Symantec 20091.2.0.41 2010.01.20 Backdoor.Tidserv —————————————————————————————————————————- Additional information File size: 21504 bytes MD5 : 548c2a5a18903898a8b141942f792f91 SHA1 : bf5ee152f2b8f8b2fd7c6520c303d2d85f5745e2 SHA256: e418b60091f47f572f0fe8b69554b8dc1734d8db43945b2d28ff0494947c4f3d —————————————————————————————————————————- Installation [...]
Removed: autorun.inf
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\malware.exe Removed: C:\autorun.inf —————————————————————————————————————————- You must restore the original versions of these files: —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.25 Rogue:W32/SpyGuard.gen!A Kaspersky 7.0.0.125 2010.01.25 Packed.Win32.Tdss.e McAfee 5871 2010.01.24 DNSChanger.f.gen.a Microsoft 1.5405 2010.01.25 Trojan:Win32/Alureon.gen!J NOD32 4802 2010.01.24 a variant of Win32/Kryptik.CN Symantec 20091.2.0.41 2010.01.25 Backdoor.Tidserv —————————————————————————————————————————- [...]
Removed: dnsq.dll, autorun.inf, ~.exe.33734.exe, ~.exe.33796.exe
Alex NightWatcher: Solved! Fix it immediately: Malware: C:\sand-box\setup.exe Removed: C:\WINDOWS\system32\dnsq.dll C:\autorun.inf C:\Documents and Settings\All Users\Start Menu\Programs\Startup\~.exe.33734.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\~.exe.33796.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.04 Suspicious:W32/Riskware!Online Kaspersky 7.0.0.125 2010.01.04 Trojan.Win32.Antavmu.ere McAfee 5851 2010.01.04 Generic Dropper!bbx Microsoft 1.5302 2010.01.04 Trojan:Win32/Malat NOD32 4743 2010.01.04 probably a variant of Win32/TrojanDropper.Agent Symantec 20091.2.0.41 [...]



