Home Malware Programs Worms Worm.Win32.AutoIt.ux

Worm.Win32.AutoIt.ux

Posted: March 2, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 412
First Seen: January 18, 2011
Last Seen: July 13, 2021
OS(es) Affected: Windows

The Worm.Win32.AutoIt.ux worm hides in your system folder and may disable security and system maintenance programs required by Windows for healthy functioning. Worm.Win32.AutoIt.ux attempts to proliferate through networks and removable drive devices and will conceal itself in folders central to your system. For the sake of your own computer's security as well as for the sake of other computers that may be infected, you should try to delete Worm.Win32.AutoIt.ux expediently before it can spread or attack your computer in earnest.

Worm.Win32.AutoIt.ux Will Travel (to Your Computer!)

Worm.Win32.AutoIt.ux is able to attack many different versions of Windows, including Windows 7. Worm.Win32.AutoIt.ux is been observed to gather IP addresses from machines sharing a network with the infected system, allowing Worm.Win32.AutoIt.ux to infect the others through buffer overrun-based vulnerabilities. Worm.Win32.AutoIt.ux can also launch its own servers and may be able to use MAPI functions and email programs to spread itself.

Any infected system connected to the Internet is in danger of spreading the Worm.Win32.AutoIt.ux infection; even offline computers may spread Worm.Win32.AutoIt.ux through removable drive-based peripheral devices. Protecting yourself from Worm.Win32.AutoIt.ux in large part requires the constant use of trustworthy anti-malware programs that can repel the infection even through shared network files and other methods of entry.

A Sum Up of Worm.Win32.AutoIt.ux's Potential Damage

A computer that has Worm.Win32.AutoIt.ux on it will suffer several ill effects, most prominently in terms of security:

  • The Worm.Win32.AutoIt.ux worm will attempt to conceal itself in your operating system folder. This behavior can indirectly damage your computer if Worm.Win32.AutoIt.ux attempts to overwrite or corrupt an essential system file.
  • Worm.Win32.AutoIt.ux will add entries to the registry to let Worm.Win32.AutoIt.ux run from a normal boot without being easily detected.
  • Even checking for the running process in Task Manager may not work, because this PC threat can also disable your Task Manager! Lack of access to Task Manager will neuter your ability to detect running processes and may make it very difficult to locate or shut down worms and other malware like Worm.Win32.AutoIt.ux.
  • Along with disabling your Task Manager, Worm.Win32.AutoIt.ux may also prevent you from using the Registry Editor. This prevents you from finding Worm.Win32.AutoIt.ux's registry entries and deleting them manually. Malware may abuse unfettered access to your registry to run in the background of the Windows environment every time your computer starts.
  • There have also been incidents of Worm.Win32.AutoIt.ux disabling the System Restore capability. This is used to 'roll back' the system to a previous stable state, and without this function, your computer may need a total reinstallation from scratch.

The extreme risks presented by this worm mandate deleting Worm.Win32.AutoIt.ux swiftly. If Worm.Win32.AutoIt.ux prevents you from accessing programs required to accomplish this, you may need to use the Safe Mode boot option. This mode may prevent Worm.Win32.AutoIt.ux from running, which will let you clean Worm.Win32.AutoIt.ux out and resume a normal wormless life.

Aliases

Trojan/Win32.Pher [Antiy-AVL]TR/Dldr.Pher.GKP.9 [AntiVir]Mal/Behav-053 [Sophos]Trojan-Downloader.Win32.Pher.gkp [Kaspersky]Artemis!14D0C818B8B4 [McAfee]Trojan.Fakesec-123 [ClamAV]a variant of Win32/Kryptik.IEG [NOD32]Generic4.BAIF [AVG]not-a-virus:AdWare.Win32.Agent [Ikarus]Adware/Win32.Agent [AhnLab-V3]AdWare/Win32.Agent.gen [Antiy-AVL]Adware/SilentBar.C [AntiVir]not-a-virus:AdWare.Win32.Agent.umm [Kaspersky]Hiloti.CO [AVG]W32/Hiloti.D!tr [Fortinet]
More aliases (175)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\CA4E81200F3A058450671CE4F9205BCE\configdat700mod.exe File name: configdat700mod.exe
Size: 1.05 MB (1052672 bytes)
MD5: 16a11a616630c252d35977ce80518f44
Detection count: 152
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\CA4E81200F3A058450671CE4F9205BCE
Group: Malware file
Last Updated: July 13, 2021
%WINDIR%\system32\userini.exe File name: userini.exe
Size: 24.57 KB (24576 bytes)
MD5: 0c3b0fa6dbb545519c6e119d6ffd60a3
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 24, 2011
%APPDATA%\RclDriver64.exe File name: RclDriver64.exe
Size: 135.68 KB (135680 bytes)
MD5: cfed9efb3deb7002c8d1cb6db35b413f
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 19, 2011
%USERPROFILE%\Start Menu\Programs\Startup\4jp5omaz7.exe File name: 4jp5omaz7.exe
Size: 70.65 KB (70656 bytes)
MD5: d7456f2dcb05df7a2884d49b4e61cecd
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 24, 2011
%PROGRAMFILES%\SimilarGroup\Similar Web\SimilarWeb.dll File name: SimilarWeb.dll
Size: 618.49 KB (618496 bytes)
MD5: c8e07056f4a1f522e657f4e5ae6f37be
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\SimilarGroup\Similar Web
Group: Malware file
Last Updated: February 1, 2011
%APPDATA%\83145\bbzzkzz17.exe File name: bbzzkzz17.exe
Size: 3.84 MB (3847680 bytes)
MD5: 2511dd11dad252ed2616c471cf33b0c0
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\83145
Group: Malware file
Last Updated: January 24, 2011
%WINDIR%\mike151.exe File name: mike151.exe
Size: 173.05 KB (173056 bytes)
MD5: 44497075150a159a93c1f1eabb4213b1
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: January 19, 2011
%WINDIR%\system32\winfiles.exe File name: winfiles.exe
Size: 578.74 KB (578748 bytes)
MD5: 88cb90d511782647bd45022f1db758dc
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 18, 2011
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe File name: vsbntlo.exe
Size: 40.96 KB (40960 bytes)
MD5: 0141ddddec5983aa91aacb11b13769ce
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811
Group: Malware file
Last Updated: January 24, 2011
%APPDATA%\4960\bbzzkzz18.exe File name: bbzzkzz18.exe
Size: 3.84 MB (3848192 bytes)
MD5: a11bd1118a9067326803fba77b942a95
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\4960
Group: Malware file
Last Updated: January 24, 2011
%WINDIR%\neviadp.dll File name: neviadp.dll
Size: 90.11 KB (90112 bytes)
MD5: 7024337bd043bc1f71eec0e030b7baf0
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%
Group: Malware file
Last Updated: January 26, 2011
C:\Winnet\WinSockx.exe File name: WinSockx.exe
Size: 1.56 MB (1569792 bytes)
MD5: 986c645fad43693385ff4e2219247aed
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Winnet
Group: Malware file
Last Updated: January 19, 2011
Loading...