Threat Database Worms Worm.AutoRun.eav

Worm.AutoRun.eav

By LoneStar in Worms

Worm.AutoRun.eav is a computer worm parasite. Worm.AutoRun.eav has been known to be automatically updated through malicious sites and then load when Windows starts. Worm.AutoRun.eav may also plant malicious Windows registry keys that automatically run making it difficult to remove from a computer without the help of a spyware removal application.

File System Details

Worm.AutoRun.eav may create the following file(s):
# File Name Detections
1. Imgtask.exe
2. XP-27EE4BE0.EXE
3. Msmsgs.exe
4. cmd.exe
5. ipilrws.exe
6. Mixa.exe
7. XP-71F06FE8.EXE
8. BEA23C.EXE
9. SilentSoftech.exe
10. scrss.exe
11. kvtrwkcc.exe
12. fuwuqi.exe
13. vshost32.exe
14. guangd.exe
15. windowsmp.exe
16. userini.exe
17. 6FB219.EXE
18. 8EBE6FCF.DLL
19. CSRSS.exe
20. system.exe
21. XP-CF959062.EXE
22. XP-D754771A.EXE
23. XP-337B8E53.EXE
24. XP-87B203C2.EXE
25. XP-4D887B29.EXE
26. XP-CE734A3C.EXE
27. XP-5ADC2FB8.EXE
28. XP-F180A41E.EXE
29. XP-12C950AE.EXE
30. XP-3451AFB8.EXE
31. XP-AA54AD69.EXE
32. XP-A252657D.EXE
33. XP-C748D768.EXE
34. userinit.exe
35. XP-8F09BDB0.EXE
36. XP-822A840F.EXE
37. XP-2D39A46D.EXE
38. XP-84978424.EXE
39. Application Datasvchost.exe
40. winlog.exe
41. win32osf.exe
42. ntdetect.com
43. FlashGuard.exe
44. cvlu.exe
45. explorer.exe
46. systtray.exe
47. MAgent.exe
48. XP-EA1E4442.EXE
49. XP-30ABA011.EXE
50. winsys.exe
51. Thumbs.exe
52. fool1.dll
53. Win24DLL.exe
54. smss.exe
55. aebfcbddecdfffeca.dll
56. explorcr.exe
57. kislab.exe
58. 83B2C82D.DLL
59. cvasds0.dll
60. services.exe
61. lsass.exe
62. XP-09A09F1E.EXE
63. XP-3E5A95DF.EXE
64. XP-5ED4BC61.EXE
65. XP-172566D2.EXE
66. XP-C8C16F42.EXE
67. XP-F3603667.EXE
68. XP-CE0B6B01.EXE
69. XP-2B689D56.EXE
70. XP-85A6D8DD.EXE
71. XP-F09415CE.EXE
72. XP-6BB4378C.EXE
73. XP-D41D8CD9.EXE
74. XP-17010165.EXE
75. XP-364C086F.EXE
76. rundli32.exe
77. XP-38B8CEBE.EXE
78. rundll56.exe
79. XP-DCB3C72C.EXE
80. winlogon.exe
81. ahr.exe
82. XP-6A3A0D20.EXE
83. xxz[1].exe
84. msupdt.exe
85. E05A84.EXE
86. SVCHOST.exe
87. cftmom.exe
88. cftmon.exe
89. GuelmimG.bat
90. qbbtqcy.exe
91. Syswin.exe
92. svchots.exe
93. SVCHOST32.EXE
94. afaadacbadddc.dll
95. KEYBOARD.exe
96. scvhost.exe
97. init.exe
98. fffddeabacfda.dll
99. tsay.exe
100. herss.exe
101. WindowsLive.exe
102. JACKsmall.exe
103. iexplorer.exe
104. XP-590822A9.EXE
105. XP-E044478C.EXE
106. XP-DDA58EAE.EXE
107. XP-6CF365E3.EXE
108. XP-F787D259.EXE
109. XP-0EF5525C.EXE
110. XP-21470116.EXE
111. XP-904B231F.EXE
112. XP-12B7E2EE.EXE
113. XP-E7D6DD34.EXE
114. XP-C8889B57.EXE
115. XP-042EC9AF.EXE
116. XP-5C37B42E.EXE
117. sysdiag64.exe
118. XP-8FF03DFF.EXE
119. XP-C6BBD855.EXE
120. UbiRg.exe
121. cftu.exe
122. sWx.exe
123. ohydy.exe
124. M7K1H3A6.vbs

Registry Details

Worm.AutoRun.eav may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Msmsgs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ E05A84
RUNNING PROGRAM\explorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ RunJava2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ImgTask
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-27EE4BE0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ntuser
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ cftmom
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\USERINIT\ userinit
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ FlashGuard
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ App
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Win32 Console
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ egrrgdk

Trending

Most Viewed

Loading...