Home Malware Programs Worms Worm.Win32.AutoRun.nn

Worm.Win32.AutoRun.nn

Posted: September 6, 2011

Threat Metric

Ranking: 8,265
Threat Level: 1/10
Infected PCs: 2,265
First Seen: September 6, 2011
Last Seen: October 1, 2023
OS(es) Affected: Windows

Worm.Win32.AutoRun.nn is recognized as a malignant computer worm, which is programmed to damage the compromised PC system or spy on the affected user's content. Worm.Win32.AutoRun.nn can copy itself via email, instant messaging and computer system exploits. When Worm.Win32.AutoRun.nn is executed, it issues malicious files and attaches them to existing files. Worm.Win32.AutoRun.nn also conceals the original files and overwrites them with their own body, so most of the files that you see are not the original ones but the files created by Worm.Win32.AutoRun.nn. You should delete Worm.Win32.AutoRun.nn before it harms your machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Documents and Settings\<username>\Application Data\[RANDOM CHARACTERS] File name: C:\Documents and Settings\<username>\Application Data\[RANDOM CHARACTERS]
Group: Malware file
C:\Documents and Settings\<username>\Local Settings\Temporary Internet Files\[clear all] File name: C:\Documents and Settings\<username>\Local Settings\Temporary Internet Files\[clear all]
Group: Malware file
C:\Documents and Settings\<username>\Local Settings\Temp\[clear all] File name: C:\Documents and Settings\<username>\Local Settings\Temp\[clear all]
Group: Malware file
C:\autorun.inf File name: C:\autorun.inf
Mime Type: unknown/inf
Group: Malware file
C:\recycler.exe File name: C:\recycler.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\[RANDOM CHARACTERS].exe File name: C:\[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\WINDOWS\system32\[RANDOM CHARACTERS].inf File name: C:\WINDOWS\system32\[RANDOM CHARACTERS].inf
Mime Type: unknown/inf
Group: Malware file
C:\WINDOWS\system32\[RANDOM CHARACTERS].dll File name: C:\WINDOWS\system32\[RANDOM CHARACTERS].dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\WINDOWS\system32\[RANDOM CHARACTERS].exe File name: C:\WINDOWS\system32\[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%APP%\Debugger

Additional Information

The following URL's were detected:
https://feed.musicstreamsearch.com/?q=
Loading...