Threat Database Worms Worm.MSIL.Autorun

Worm.MSIL.Autorun

By CagedTech in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 492
First Seen: February 22, 2011
Last Seen: August 30, 2022
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Generic19.BKFX
DrWeb Trojan.FakeAV.302
McAfee FakeAlert-SpyPro.gen.ak
McAfee-GW-Edition Artemis!8AA4E9DAF943
AntiVir TR/Crypt.ZPACK.Gen
Sophos Mal/FakeAV-CS
BitDefender Gen:Variant.Kazy.13722
Symantec Trojan.FakeAV!gen42
NOD32 a variant of Win32/Kryptik.LAS
McAfee FakeAlert-MalDoctor.v
Panda Trj/CI.A
AVG SHeur3.BPVG
Ikarus Gen.Variant.Kazy
BitDefender Gen:Variant.Kazy.11748
McAfee Artemis!B61FF15058AA

File System Details

Worm.MSIL.Autorun may create the following file(s):
# File Name MD5 Detections
1. csrss.exe 29459293531d7ecbf61d62de7527ba1f 28
2. ntuser.exe a4294fdb2b53c0e047a879a76bfc7bbf 22
3. Uw.exe c4e4f732b392a32b3224e49f87efeca9 10
4. AdobeUpdate.exe 8aa4e9daf943122c6152a424d23977bd 5
5. csccpl.dll e9f266cfab60b439f660df32087cb06f 2
6. explorer.exe 63c013673681430fb1f80dda49d757de 2
7. wjdrive32.exe 01e416d5891a5a87520096b723529f37 2
8. ckffsglyhsn.exe ada3fd631969ffac103ed635a7402610 1
9. jucheck.exe 4a556caf6116bb0a2c26a8c318276782 1
10. nrload7E.dll b61ff15058aae99c209afb0ac579e662 1
More files

Registry Details

Worm.MSIL.Autorun may create the following registry entry or registry entries:
Regexp file mask
%USERPROFILE%\Contacts\ntuser.exe
%USERPROFILE%\Contacts\SQlServer.exe
%USERPROFILE%\Contacts\Windows
%WINDIR%\system\csrss.exe

Related Posts

Trending

Most Viewed

Loading...