Home Malware Programs Worms Worm.Autoit

Worm.Autoit

Posted: March 20, 2009

Threat Metric

Threat Level: 9/10
Infected PCs: 6,750
First Seen: July 24, 2009
Last Seen: September 12, 2024
OS(es) Affected: Windows

Worm.Autoit, also known as Trojan-Downloader.Win32.Agent.akh, is a worm classified as a network worm. Worm.Autoit is designed to make a backdoor through which an attacker may get access to control your machine. Worm.Autoit may distribute itself through network shares. After execution, Worm.Autoit will configure your operating system to run Worm.Autoit on every boot and will connect to an IRC server. Worm.Autoit may avoid several commercial firewall from detecting it. Worm.Autoit is a serious threat and is recommended to be removed immediately.

Aliases

Generic4_c.BQXL [AVG]W32/Autoit.TID!tr [Fortinet]Trojan-Downloader.Win32.Homa [Ikarus]Malware/Win32.Generic [AhnLab-V3]Backdoor:Win32/Fynloski.A [Microsoft]Troj/Agent-TID [Sophos]BDS/Fynloski.A.1760 [AntiVir]Trojan.PWS.Spy.11887 [DrWeb]Trojan.Autoit.APZ [BitDefender]Trojan.Autoit-108 [ClamAV]Win32.Autoit [eSafe]VBS:Malware-gen [Avast]Win32/Injector.JDF [NOD32]Artemis!5904A2FE2F28 [McAfee]Generic Malware [Panda]
More aliases (369)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Init.exe File name: Init.exe
Size: 2.68 MB (2689536 bytes)
MD5: c564ad11b786bd62fbc230edf9d471ee
Detection count: 675
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 28, 2017
c:\Win\lsass.exe File name: lsass.exe
Size: 551.66 KB (551669 bytes)
MD5: 56dec30ef90d4b0439349bb23dc32b51
Detection count: 138
File type: Executable File
Mime Type: unknown/exe
Path: c:\Win\lsass.exe
Group: Malware file
Last Updated: August 26, 2024
%PROGRAMFILES%\Internet Explorer\services.exe File name: services.exe
Size: 1.44 MB (1441280 bytes)
MD5: aeec0549767793515a834b4f93cca250
Detection count: 105
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Internet Explorer
Group: Malware file
Last Updated: September 28, 2010
KHATRA.exe File name: KHATRA.exe
Size: 576.31 KB (576319 bytes)
MD5: dba6f64dbdeb9d641f80c0f5521ad88c
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 21, 2019
Msmsgs.exe File name: Msmsgs.exe
Size: 215.55 KB (215552 bytes)
MD5: 15ca447847e8b1d6d3e7423b10d863f1
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 19, 2010
mgy.exe File name: mgy.exe
Size: 16.41 MB (16417245 bytes)
MD5: c08f80d67c2d2ffa2b4623d66ea1aacc
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 23, 2010
D:\$RECYCLE.BIN.exe File name: $RECYCLE.BIN.exe
Size: 1.55 MB (1550848 bytes)
MD5: 318b786ab8d85edcdc50e676091de6ed
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: D:\$RECYCLE.BIN.exe
Group: Malware file
Last Updated: November 26, 2024
zchMiB.exe File name: zchMiB.exe
Size: 484.57 KB (484573 bytes)
MD5: 0fb37687780f63ddb0e21f8240c3a37d
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
C:\Victoria536\Help\Ukraine.exe File name: Ukraine.exe
Size: 1.54 MB (1544097 bytes)
MD5: 796877178b524b3d21d53328cdbfcdb4
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: C:\Victoria536\Help\Ukraine.exe
Group: Malware file
Last Updated: March 27, 2024
%SYSTEMDRIVE%\Qoobox\Quarantine\C\Win\lsass.exe.vir File name: lsass.exe.vir
Size: 551.66 KB (551669 bytes)
MD5: d01ef1cc38f805230942d2bb55bfd976
Detection count: 21
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\Qoobox\Quarantine\C\Win\lsass.exe.vir
Group: Malware file
Last Updated: August 19, 2020
D:\ \Ciencias Naturales\biologia II\Bachiller en Ciencias y Humanidades - Instituto Técnico Europeo en Salud_files.exe File name: Bachiller en Ciencias y Humanidades - Instituto Técnico Europeo en Salud_files.exe
Size: 1.69 MB (1696673 bytes)
MD5: dcae9fc654eba45a4385b8484ec613b2
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: D:\ \Ciencias Naturales\biologia II\Bachiller en Ciencias y Humanidades - Instituto Técnico Europeo en Salud_files.exe
Group: Malware file
Last Updated: August 13, 2022
%WINDIR%\AppPatch\smss.exe File name: smss.exe
Size: 229.21 KB (229218 bytes)
MD5: 13fabe7222c2768f33691050140bd3b5
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\AppPatch
Group: Malware file
Last Updated: October 14, 2010
%ALLUSERSPROFILE%\Local Settings\Temp\msaows.bat File name: msaows.bat
Size: 806.53 KB (806535 bytes)
MD5: 9e50c57b39ccced502a75d7fc2f15da5
Detection count: 16
File type: Batch file
Mime Type: unknown/bat
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: July 12, 2013
mschr.exe File name: mschr.exe
Size: 476.93 KB (476938 bytes)
MD5: 686596d1ca85cd175b8b90bc41141f83
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
psvrr.exe File name: psvrr.exe
Size: 465.87 KB (465874 bytes)
MD5: 430cc016de5b674808fa46ed4d866592
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathmyloveever.exeRegexp file mask%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Init.exe%HOMEDRIVE%\logoneui.exe

Related Posts

Loading...