au.exe - Dangerous
%windir%\au.exe
Manual removal instructions:
Antivirus Report of %windir%\au.exe:
%windir%\au.exe
I-Worm.Bagle.b
This worm spreads via the Internet as attachments to infected emails.
The infected messages have the following characteristics:
Header:
ID x... thanks
with x being a string of random characters.
Body:
Yours ID x
--
Thank
with x being a string of random characters.
Attachment:
The attachment has a random name, with a file size of 11KB.
The worm copies itself to the Windows system directory under the name 'au.exe'.
Adds the value: "au.exe" = "%system%\au.exe"
to registry key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Also creates the following registry key:
[HKCU\SOFTWARE\Windows2000] and saves its variables there.
The worm attempts to connect to remote sites, all of which are in some way connected with the Trojan proxy server TrojanProxy.Win32.Mitglieder
Send itself to all email addresses found in files on disks.
%windir%\au.exe | Malware |
%windir%\au.exe | Dangerous |
%windir%\au.exe | High Risk |
This worm spreads via the Internet as attachments to infected emails.
The infected messages have the following characteristics:
Header:
ID x... thanks
with x being a string of random characters.
Body:
Yours ID x
--
Thank
with x being a string of random characters.
Attachment:
The attachment has a random name, with a file size of 11KB.
The worm copies itself to the Windows system directory under the name 'au.exe'.
Adds the value: "au.exe" = "%system%\au.exe"
to registry key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Also creates the following registry key:
[HKCU\SOFTWARE\Windows2000] and saves its variables there.
The worm attempts to connect to remote sites, all of which are in some way connected with the Trojan proxy server TrojanProxy.Win32.Mitglieder
Send itself to all email addresses found in files on disks.
Dmitry Sokolov:
I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.