Threat Database Worms Worm.MSIL.Autorun

Worm.MSIL.Autorun

By CagedTech in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 491
First Seen: February 22, 2011
Last Seen: August 30, 2022
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Generic19.BKFX
DrWeb Trojan.FakeAV.302
McAfee FakeAlert-SpyPro.gen.ak
McAfee-GW-Edition Artemis!8AA4E9DAF943
AntiVir TR/Crypt.ZPACK.Gen
Sophos Mal/FakeAV-CS
BitDefender Gen:Variant.Kazy.13722
Symantec Trojan.FakeAV!gen42
NOD32 a variant of Win32/Kryptik.LAS
McAfee FakeAlert-MalDoctor.v
Panda Trj/CI.A
AVG SHeur3.BPVG
Ikarus Gen.Variant.Kazy
BitDefender Gen:Variant.Kazy.11748
McAfee Artemis!B61FF15058AA

File System Details

Worm.MSIL.Autorun may create the following file(s):
# File Name MD5 Detections
1. ntuser.exe 4d751cb03d12ec3af2077c773fc66420 97
2. csrss.exe ee83b131248d447367a98a4b27c5c7d0 74
3. csrss.exe 29459293531d7ecbf61d62de7527ba1f 28
4. ntuser.exe a4294fdb2b53c0e047a879a76bfc7bbf 22
5. csrss.exe 0cdca4f6fd78663110c700844b60562f 13
6. Uw.exe c4e4f732b392a32b3224e49f87efeca9 10
7. AdobeUpdate.exe 8aa4e9daf943122c6152a424d23977bd 5
8. csccpl.dll e9f266cfab60b439f660df32087cb06f 2
9. explorer.exe 63c013673681430fb1f80dda49d757de 2
10. wjdrive32.exe 01e416d5891a5a87520096b723529f37 2
11. ckffsglyhsn.exe ada3fd631969ffac103ed635a7402610 1
12. jucheck.exe 4a556caf6116bb0a2c26a8c318276782 1
13. nrload7E.dll b61ff15058aae99c209afb0ac579e662 1

Registry Details

Worm.MSIL.Autorun may create the following registry entry or registry entries:
Regexp file mask
%USERPROFILE%\Contacts\ntuser.exe
%USERPROFILE%\Contacts\SQlServer.exe
%USERPROFILE%\Contacts\Windows
%WINDIR%\system\csrss.exe

Related Posts

Trending

Most Viewed

Loading...