Home Malware Programs Worms MSIL.Autorun.H

MSIL.Autorun.H

Posted: February 22, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 1,150
First Seen: February 22, 2011
Last Seen: August 30, 2022
OS(es) Affected: Windows

Aliases

Generic19.BKFX [AVG]Trojan.FakeAV.302 [DrWeb]FakeAlert-SpyPro.gen.ak [McAfee]Artemis!8AA4E9DAF943 [McAfee-GW-Edition]TR/Crypt.ZPACK.Gen [AntiVir]Mal/FakeAV-CS [Sophos]Gen:Variant.Kazy.13722 [BitDefender]Trojan.FakeAV!gen42 [Symantec]a variant of Win32/Kryptik.LAS [NOD32]FakeAlert-MalDoctor.v [McAfee]Trj/CI.A [Panda]SHeur3.BPVG [AVG]Gen.Variant.Kazy [Ikarus]Gen:Variant.Kazy.11748 [BitDefender]Artemis!B61FF15058AA [McAfee]
More aliases (78)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Contacts\ntuser.exe File name: ntuser.exe
Size: 5.74 MB (5747712 bytes)
MD5: 4d751cb03d12ec3af2077c773fc66420
Detection count: 227
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Contacts\ntuser.exe
Group: Malware file
Last Updated: February 16, 2021
%WINDIR%\system\csrss.exe File name: csrss.exe
Size: 184.59 KB (184598 bytes)
MD5: ee83b131248d447367a98a4b27c5c7d0
Detection count: 173
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: June 29, 2017
%WINDIR%\system\csrss.exe File name: csrss.exe
Size: 89.36 KB (89366 bytes)
MD5: 29459293531d7ecbf61d62de7527ba1f
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: June 29, 2017
%USERPROFILE%\nrload7E.dll File name: nrload7E.dll
Size: 606.2 KB (606208 bytes)
MD5: b61ff15058aae99c209afb0ac579e662
Detection count: 65
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%
Group: Malware file
Last Updated: February 28, 2011
%USERPROFILE%\Contacts\ntuser.exe File name: ntuser.exe
Size: 14.56 MB (14568448 bytes)
MD5: a4294fdb2b53c0e047a879a76bfc7bbf
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Contacts
Group: Malware file
Last Updated: November 23, 2016
%WINDIR%\system\csrss.exe File name: csrss.exe
Size: 14.54 MB (14540800 bytes)
MD5: 0cdca4f6fd78663110c700844b60562f
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: June 29, 2017
%APPDATA%\Adobe\AdobeUpdate.exe File name: AdobeUpdate.exe
Size: 39.93 KB (39936 bytes)
MD5: 8aa4e9daf943122c6152a424d23977bd
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Adobe
Group: Malware file
Last Updated: February 28, 2011
%TEMP%\aqascaqoo\ckffsglyhsn.exe File name: ckffsglyhsn.exe
Size: 242.17 KB (242176 bytes)
MD5: ada3fd631969ffac103ed635a7402610
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\aqascaqoo
Group: Malware file
Last Updated: March 21, 2011
%WINDIR%\system32\csccpl.dll File name: csccpl.dll
Size: 59.39 KB (59392 bytes)
MD5: e9f266cfab60b439f660df32087cb06f
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: February 23, 2011
C:\drivers\explorer.exe File name: explorer.exe
Size: 899.58 KB (899584 bytes)
MD5: 63c013673681430fb1f80dda49d757de
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\drivers
Group: Malware file
Last Updated: February 28, 2011

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%USERPROFILE%\Contacts\ntuser.exe%USERPROFILE%\Contacts\SQlServer.exe%USERPROFILE%\Contacts\Windows%WINDIR%\system\csrss.exe
Loading...