Home Malware Programs Worms Worm:BAT/Autorun.R

Worm:BAT/Autorun.R

Posted: November 18, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 40
First Seen: November 18, 2011
OS(es) Affected: Windows

Worm:BAT/Autorun.R is a worm, which enters the targeted computer system and masks itself by using file names of genuine programs. Worm:BAT/Autorun.R messes up the infected computer system. Worm:BAT/Autorun.R circulates by copying itself to removable drives. Once Worm:BAT/Autorun.R invades the affected PC, it copies its files in different locations of the machine and starts functioning. Worm:BAT/Autorun.R will run automatically every time you start Windows. Worm:BAT/Autorun.R might create files with different extensions of filenames. Worm:BAT/Autorun.R creates a certain temporary file with a random filename in order to stay unnoticed. Worm:BAT/Autorun.R uses the names of Microsoft's software products to disguise its files. Worm:BAT/Autorun.R modifies parameters of removable disks to distribute Worm:BAT/Autorun.R. Worm:BAT/Autorun.R can also contact remote servers to communicate between programs on different PCs.

Aliases

Trojan/Win32.Jorik [AhnLab-V3]BackDoor.Gbot.1589 [DrWeb]Trojan.Win32.Jorik.Gbot.ryz [Kaspersky]Backdoor.Cycbot!gen9 [Symantec]a variant of Win32/Kryptik.VSW [NOD32]BackDoor-EXI.gen.ad [McAfee]Generic25.CIIW [AVG]Artemis!BADBBE44CEE4 [McAfee-GW-Edition]TR/Jorik.Delf.auo [AntiVir]Trojan.DownLoader5.17006 [DrWeb]Trojan.Generic.6925963 [BitDefender]Trojan.Win32.Jorik.Delf.auo [Kaspersky]Win32:Rootkit-gen [Rtk] [Avast]Generic.tfr!z [McAfee]Generic23.BDEQ [AVG]
More aliases (83)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Recycle.Bin\Recycle.Bin.exe File name: Recycle.Bin.exe
Size: 159.23 KB (159232 bytes)
MD5: f8949c0e415a4b87ab58d2002b7e8a27
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Recycle.Bin
Group: Malware file
Last Updated: November 21, 2011
%WINDIR%\system32\svcsrss.exe File name: svcsrss.exe
Size: 69.63 KB (69632 bytes)
MD5: c35ff402d70790e82db3371fa2a24af9
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 18, 2011
%TEMP%\e.exe File name: e.exe
Size: 990.72 KB (990720 bytes)
MD5: badbbe44cee4dd12bfe668521bc0b18a
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 23, 2011
%APPDATA%\Crystal.exe File name: Crystal.exe
Size: 719.56 KB (719567 bytes)
MD5: 1ff679cfddd078a286639e4497e6ca66
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: November 21, 2011
%PROGRAMFILES%\JTS\JTS.exe File name: JTS.exe
Size: 1.76 MB (1762304 bytes)
MD5: c802f1e3d60c919455d886462b4f3784
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\JTS
Group: Malware file
Last Updated: November 21, 2011
%TEMP%\2B4F.tmp File name: 2B4F.tmp
Size: 276.48 KB (276480 bytes)
MD5: 05ab99486233420f0c5403de3e99b306
Detection count: 6
File type: Temporary File
Mime Type: unknown/tmp
Path: %TEMP%
Group: Malware file
Last Updated: November 23, 2011
Loading...