Threat Database Trojans Trojan.Autorun.S

Trojan.Autorun.S

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,349
Threat Level: 80 % (High)
Infected Computers: 8
First Seen: September 20, 2021
Last Seen: June 26, 2026
OS(es) Affected: Windows

The detection of Trojan.Autorun.S on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Autorun.S?

Trojan.Autorun.S is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan.Autorun.S" suggests that it may be related to the autorun feature in Windows, which allows programs to run automatically when a device is connected or a disk is inserted. However, without more specific information, it's difficult to determine the exact nature and behavior of this particular threat.

How Trojan.Autorun.S Operates

Trojan horses like Trojan.Autorun.S typically operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can perform a variety of malicious actions, such as stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system. They may also attempt to spread to other systems through various means, including removable drives, network connections, or email attachments.

It's worth noting that the exact behavior of Trojan.Autorun.S may vary, and its primary goal may be to serve as a gateway for other malicious activities. The lack of specific information about this threat makes it challenging to provide detailed analysis, but it's clear that prompt removal is necessary to prevent potential harm.

Symptoms of Infection

Systems infected with Trojan.Autorun.S may exhibit a range of symptoms, including unusual system behavior, slow performance, or unexpected pop-ups and alerts. Users may also notice that their system settings have been changed without their consent or that unfamiliar programs are running in the background. However, some infections may not display any noticeable symptoms, making regular system scans and monitoring essential for detection.

How to Remove Trojan.Autorun.S

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

It's crucial to follow these steps carefully and use reputable tools to avoid further compromising your system. If you're unsure about any part of the removal process, consider seeking assistance from a professional.

Conclusion

The detection of Trojan.Autorun.S is a serious issue that requires prompt and careful action to remove the threat and prevent future infections. By understanding the nature of this malware and following the removal steps outlined above, you can help protect your system and sensitive information from potential harm. Remember to always be cautious when installing software, opening email attachments, or inserting removable devices, and keep your system and security software up to date to minimize the risk of infection.

Analysis Report

General information

Family Name: Trojan.Autorun.S
Signature status: Hash Mismatch

Known Samples

MD5: 2141a7fb72cc3dc42e8a87855e7d67bf
SHA1: bcb4dd1814b65ac4803c0bca4e4c471f07b0e81b
SHA256: A085B342D3E8E17C194E7E546C2D3A764FEFB961FB79A266AE382399CDA845C9
File Size: 173.43 KB, 173432 bytes
MD5: d79e93ffaadc4ce22a145d22e47595cb
SHA1: a4ba5989a45366d670cb2565908f4487debc0ab8
SHA256: 6B09F78B49BBFE0635A140E5ADA87C3CBC39A71DF5B7C78CB8D73673E0B50C77
File Size: 169.41 KB, 169408 bytes
MD5: 245fcdc6c2752206e4675b652886131a
SHA1: 3f7f335bef61349cd6fa4f891605d6acbcc2b327
SHA256: 97F191DD31123A67A90C49121B4B7AB39F71A13AAB18FB37313820DFC212C54F
File Size: 181.70 KB, 181696 bytes
MD5: 4e5570aeda4c9685aa5980cd9ccc12ac
SHA1: dd7f5a1564d507f4baebaf7c7553ff338d843d37
SHA256: 2F4F982158AF12411E9BD853674A60BBABD2FE88AEB19C503AC071267BDEA5A3
File Size: 177.98 KB, 177983 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Adobe Systems Incorporated
File Description Eula display
File Version
  • 9.5.0.270
  • 9.3.0.148
  • 9.1.0.0
  • 1.0.0.1
Internal Name Eula.exe
Legal Copyright
  • (c) Adobe Systems Incorporated. All rights reserved.
  • Copyright 2008 Adobe Systems Incorporated. All rights reserved.
  • Copyright 2008-2010 Adobe Systems Incorporated and its licensors. All rights reserved.
Original Filename Eula.exe
Product Name EULA
Product Version
  • 9.5.0.270
  • 9.3.0.148
  • 9.1.0.0
  • 1.0.0.1

Digital Signatures

Signer Root Status
Adobe Systems, Incorporated VeriSign Class 3 Code Signing 2004 CA Hash Mismatch

File Traits

  • 2+ executable sections
  • big overlay
  • HighEntropy
  • SusSec
  • x86

Block Information

Total Blocks: 262
Potentially Malicious Blocks: 23
Whitelisted Blocks: 223
Unknown Blocks: 16

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 ? 0 ? ? ? ? ? ? x 0 ? 0 0 ? x ? x ? ? ? ? x ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 1 0 1 0 1 0 2 0 1 1 2 0 2 3 1 0 0 2 2 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Autorun.S

Files Modified

File Attributes
c:\program files\common files\system\symsrv.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalldisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::uacdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::appinit_dlls C:\PROGRA~1\COMMON~1\System\symsrv.dll RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::loadappinit_dlls  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::requiresignedappinit_dlls RegNtPreCreateKey

Related Posts

Trending

Most Viewed

Loading...