Threat Database Worms Worm.AutoRun!sd6

Worm.AutoRun!sd6

Threat Scorecard

Ranking: 3,054
Threat Level: 90 % (High)
Infected Computers: 22,952
First Seen: July 24, 2009
Last Seen: September 19, 2023
OS(es) Affected: Windows

Worm.AutoRun!sd6 is a worm that can download malicious files from a remote server. Worm.AutoRun!sd6 is a network worm that typically replicates itself across existing networks. Once Worm.AutoRun!sd6 has infiltrated a system, it will create a start-up registry entry and attempt to disable the Safe Mode. Worm.AutoRun!sd6 is difficult to manually remove but it can be easily detected and removed with a recognized anti-spyware application.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Trj/Passtealer.FZ
AVG Worm/Delf.GOD
Fortinet W32/AutoRun.LW!worm
AhnLab-V3 Win-Trojan/Autorun.59392.B
Sophos W32/SillyFDC-BP
AntiVir TR/Agent.AGBR
DrWeb Win32.HLLW.Autoruner.1773
Comodo Worm.Win32.AutoRun.EY
BitDefender Trojan.Agent.AGBR
Kaspersky Worm.Win32.AutoRun.lw
ClamAV Trojan.Autorun-220
Avast Win32:AutoRun-QM [Wrm]
F-Prot W32/Worm.AXFI
NOD32 Win32/AutoRun.EY
McAfee W32/Autorun.worm.r

SpyHunter Detects & Remove Worm.AutoRun!sd6

File System Details

Worm.AutoRun!sd6 may create the following file(s):
# File Name MD5 Detections
1. database.mdb 0a456ffff1d3fd522457c187ebcf41e4 2,676
2. Adobe .scr 4798cecc36d9952ba73633c54f3468b6 33
3. Alwil Software .scr 877f32a2b7b611f4080f1ee1380c71ac 32
4. kop .scr 7a0b5674ec20b6455559ca1d70dc2c55 19
5. Prolin.exe 65eeb8a0fce412d7f236f8348357d1c0 7
6. NAKEDWIF.EXE da9dba70de70dc43d6535f2975cec68d 7
7. musallat.exe 5176a58244391519e1adb48221377b58 7
8. SgiBioSrv .scr 13ae3be4d7ec63dc38b3e6dc94a20abc 6
9. Kiray.exe f22ae972aee081ec86faa30e73d9675f 6
10. musallat.exe a66f4b8186ecb503170c8ffd7977cb93 5
11. toil.exe ec8a1659c7d67a3859d515130bae3c4c 3
12. VirusShare_2ca27551e11bf054f7c5cb98eac11408 2ca27551e11bf054f7c5cb98eac11408 2
13. magistr.exe a8cfcfa06303168b5f94e0696882a3c8 2
14. VirusShare_0eb3cca824da735aa040caa012450748 0eb3cca824da735aa040caa012450748 2
15. Application Data .scr 3c59bd20783744e16f749127055b52de 1
16. stator.exe 52a3b8dda9c9f1c87b77f9aa01e6777e 1
17. fintas.exe 42b1eb959ce76f9013e8e9922305ca29 1
18. paukor.exe 7e20359dfc0b2291487f1a45c4471988 1
19. VirusShare_15c2f7ece2c6647c5e45608e39b08e34 15c2f7ece2c6647c5e45608e39b08e34 1
20. gip3.exe 644814aa418a3ae1716daa7fb484a539 1
21. musallat.exe ef0d84b6c1066a09a657e4043070730d 1
22. musallat.exe bba1a6d47a23806963911a46129fd920 1
23. musallat.exe e1de5e4408e7db707f4a366137f40510 1
24. musallat.exe 6af25dee63ba49ddd86058eb253352cd 1
25. musallat.exe 081dd2267978379f9a1864192402837e 1
26. musallat.exe 607970f9d752fc6bb5715be35704936d 1
27. musallat.exe cb5f2f48eb757d630ab7027b9fe8c4b6 1
28. naked.exe da4371bc7347d3633c0eea308c9cb444 0
29. gip1.exe dbea1cc228c9353851e06599788a5a5e 0
More files

Registry Details

Worm.AutoRun!sd6 may create the following registry entry or registry entries:
File name without path
! My Picutre.SCR
!new.scr
images.scr
New Folder.exe
Thumbs .db
windows vista setup .scr
Regexp file mask
%ALLUSERSPROFILE%\Adobe .scr
%APPDATA%\Microsoft\winlog.exe
%APPDATA%\MusaLLaT.exe
%APPDATA%\readere_lm.com
%SystemRoot%\System32\XP-[RANDOM CHARACTERS].exe
%WINDIR%\dc.exe

Directories

Worm.AutoRun!sd6 may create the following directory or directories:

%PROGRAMFILES%\windows common files
%PROGRAMFILES(x86)%\windows common files
%TEMP%\E_4
%TEMP%\E_N4

Trending

Most Viewed

Loading...