Home / Spyware Encyclopedia / Worm.AutoIt << Back

Recommendation to Automatically remove Worm.AutoIt


Our products can remove Worm.AutoIt and thousands of other Virus and Spyware automatically and instantly.

Worm.AutoIt Details


  • Category Worm
  • Discovered 6/30/2009 12:06:51 PM
  • Modified 2/23/2024 5:22:12 PM
  • Threat Level High
  • Category Description
    A Worm is a malicious program that spreads itself without any user intervention. Worms spread without attaching to or infecting other programs and files. A Worm can spread across computer networks via security holes on vulnerable machines connected to the network and also through email by sending copies of itself to everyone in the user's address book. A Worm may consume a large amount of system resources and cause the machine to become noticeably sluggish and unreliable.

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
MsRun32.exe 2064384 3, 2, 10, 055d20fb945db75d2f64b0a4bc189bf06 
e73543a6.exe 2064384 3, 2, 10, 055d20fb945db75d2f64b0a4bc189bf06 
ff1e0068.exe 2092817 3, 2, 10, 0400ec2b4dfb42043a94b9dcdcc5b52bf 
msrun32.exe 2092817 3, 2, 10, 0400ec2b4dfb42043a94b9dcdcc5b52bf 
svchost .exe 2039569 3, 2, 10, 06fc8bf31109da2dbfeefe990a824b151 
regsvr.exe 2039569 3, 2, 10, 06fc8bf31109da2dbfeefe990a824b151 
6f2ed9cf.exe 2039569 3, 2, 10, 06fc8bf31109da2dbfeefe990a824b151 
07728887.exe 2039569 3, 2, 10, 07079edbe6d1d857a24ef55be4feb1eb6 
815A4918.EXE 267089 3, 2, 12, 01d4927134f04d237092c3ab1cd34fd36 
gphone.exe 267264 3, 2, 12, 0a6e07bca5e8de6bc0147274930b52b9a 

The following Registry Entries were created:
..\Software\Microsoft\Windows\CurrentVersion\Run\\"msn messsenger"\"%win.sys32%\regsvr.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Yahoo Messengger"\"%WIN.SYS32%\gphone.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"YAHOO MESSENGGER"\"%WIN.SYS32%\SCVVHSOT.EXE"
..\Software\Microsoft\DRM\amty\"exp1"\"408406541BC5BBE4DC197A2A0C46B9ACF2F90D96B151D7C7BCBD177641EE95F662E634D70EB70FB65FC8FBF0EC312619"
..\Software\Microsoft\DRM\amty\"exp1"\"408406541BC5BBE4DC197A2A0C46B9ACF2F90D96B151D7C7BCBD177641EE95F562E634D70EB70FB65FC8FBF0EC31276E"
..\Software\Microsoft\DRM\amty\"exp1"\"408406541BC5BBE4DC197A2A0C46B9AFF2F90D96B151D7C7BCBD177641EE95F062E634D70EB70FB65FC8FBF3EC362618"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"user agent"\"%das.au.ls%\temp\svchost.com"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"user agent"\"%win.sys32%\fdisk.com"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"hotkey"\"%das.au.templates%\cache\sfcsrvc.pif"
..\Software\vlad\(Default)

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware