Home / Spyware Encyclopedia / Worm.AutoIt << Back

Recommendation to Automatically remove Worm.AutoIt


Our products can remove Worm.AutoIt and thousands of other Virus and Spyware automatically and instantly.

Worm.AutoIt Details


  • Category Worm
  • Discovered 6/30/2009 12:06:51 PM
  • Modified 2/23/2024 5:22:12 PM
  • Threat Level High
  • Category Description
    A Worm is a malicious program that spreads itself without any user intervention. Worms spread without attaching to or infecting other programs and files. A Worm can spread across computer networks via security holes on vulnerable machines connected to the network and also through email by sending copies of itself to everyone in the user's address book. A Worm may consume a large amount of system resources and cause the machine to become noticeably sluggish and unreliable.

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
411A5C8D.EXE 434504Macrosoft Corporation1.30.0000.000014441b4afe1eb5fc84471cb669622462 
korn.exe 529210 3.3.0.0e15d5e2f384b6951e9379af15276a0d4 
647705C0.EXE 535424 3.2.12.1ae127212ad67ab240818d95eb7128d25 
548FE3B2.EXE 265969 3.2.12.0fe29719a5cf07b883193c97e6c4448bd 
gphone.exe 265969 3.2.12.0fe29719a5cf07b883193c97e6c4448bd 
gphone.exe 305664 3.2.12.0da6ee1948c0ee932afa5187ff13ee226 
gphone.exe 369664 3.2.12.0b7a041e7d1781cb313fa367af21e1a5a 
gphone.exe 470433 3.2.12.08b8c0f5dbc571154fc4ebfc9c0b5ea14 
0cdf9e2c.exe 470433 3.2.12.08b8c0f5dbc571154fc4ebfc9c0b5ea14 
gphone.exe 447421 3.2.12.08075fea2f6e8f6f354445f66112451c4 

The following Registry Entries were created:
..\Software\Microsoft\Windows\CurrentVersion\Run\\"msn messsenger"\"%win.sys32%\regsvr.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Yahoo Messengger"\"%WIN.SYS32%\gphone.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"YAHOO MESSENGGER"\"%WIN.SYS32%\SCVVHSOT.EXE"
..\Software\Microsoft\DRM\amty\"exp1"\"408406541BC5BBE4DC197A2A0C46B9ACF2F90D96B151D7C7BCBD177641EE95F662E634D70EB70FB65FC8FBF0EC312619"
..\Software\Microsoft\DRM\amty\"exp1"\"408406541BC5BBE4DC197A2A0C46B9ACF2F90D96B151D7C7BCBD177641EE95F562E634D70EB70FB65FC8FBF0EC31276E"
..\Software\Microsoft\DRM\amty\"exp1"\"408406541BC5BBE4DC197A2A0C46B9AFF2F90D96B151D7C7BCBD177641EE95F062E634D70EB70FB65FC8FBF3EC362618"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"user agent"\"%das.au.ls%\temp\svchost.com"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"user agent"\"%win.sys32%\fdisk.com"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"hotkey"\"%das.au.templates%\cache\sfcsrvc.pif"
..\Software\vlad\(Default)

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware