Home Malware Programs Hacktool Worm.Win32.AutoRun.ezt

Worm.Win32.AutoRun.ezt

Posted: August 13, 2009

Threat Metric

Threat Level: 6/10
Infected PCs: 23
First Seen: July 24, 2009
OS(es) Affected: Windows

Worm.Win32.AutoRun.ezt is a computer worm that seeks to spread from computer to computer by copying itself to removable storage devices that infect other systems when the device is connected to them. Worm.Win32.AutoRun.ezt then has the ability to download additional forms of malware onto the compromised machine.

Aliases

HackTool.Tcpz (Not a Virus) [CAT-QuickHeal]Backdoor.Win32.IRCBot [Ikarus]Backdoor/Win32.IRCBot.gen [Antiy-AVL]Worm/IrcBot.11656.3 [AntiVir]Backdoor:W32/IRCBot.GUU [F-Secure]Worm.Generic.88222 [BitDefender]Backdoor.Win32.IRCBot.jsm [Kaspersky]Win32.GenericRootkit [eSafe]W32.IRCBot [Symantec]Win32/TCPZ.D [NOD32]Backdoor [K7AntiVirus]Trojan.Agent.ATV [CAT-QuickHeal]Hacktool/Tcpz.A [Panda]Generic28.BNNJ [AVG]not-a-virus:RiskTool.Win32.Tcpz [Ikarus]
More aliases (113)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



svzip.exe File name: svzip.exe
Size: 203.26 KB (203264 bytes)
MD5: e18a5ee6efab3f4e64ae32b1200e4c60
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
sv.exe File name: sv.exe
Size: 202.24 KB (202240 bytes)
MD5: 3e6a990438c37ffdaf8bbedffd6daf6e
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
svc.exe File name: svc.exe
Size: 179.2 KB (179200 bytes)
MD5: fdde49b3668c5ac1704a99d9567f0888
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
adsmsexti.exe File name: adsmsexti.exe
Size: 46.08 KB (46080 bytes)
MD5: aa86e23faa3b74d285b62accb0d53c88
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
runsql.exe File name: runsql.exe
Size: 202.75 KB (202752 bytes)
MD5: ba702d98ac626c79b7a3b012ec4a0f03
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
bload.exe File name: bload.exe
Size: 26.11 KB (26112 bytes)
MD5: 583e05807195312310a3c2d8e1eb5bfe
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1054y.exe File name: 1054y.exe
Size: 45.56 KB (45568 bytes)
MD5: 3f0132e8967a27dbf41e3fcf1f3b4dbf
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%WINDIR%\system32\drivers\minidrv32.sys File name: minidrv32.sys
Size: 11.65 KB (11656 bytes)
MD5: 8c6511826c60d64c0dbbcbb7a75fe90f
Detection count: 2
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: April 16, 2013
Loading...