• 0

Taquito.exe - What is it?


Question

Hi All,

Have you guys heard of this file?

No AntiVirus software I know detects this.

All I know about it:

Creates a RESTORE folder in the root folder

Creates a sub folder which will look like a Recycle Bin

Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe

Creates an autorun.inf with the following:

[autorun]
open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\default=1

A google results gave no results. 18 hours ago there is one result:

http://www.google.com.au/search?q=Taquito....lient=firefox-a

s1521148247650116444919xp5.th.png

Thanks,

McoreD

Link to comment
Share on other sites

25 answers to this question

Recommended Posts

  • 0

Nope, never heard of it. I can't find anything about it on the net either. It must be some kind of worm if it does what you mentioned.

Link to comment
Share on other sites

  • 0
Hi All,

Have you guys heard of this file?

No AntiVirus software I know detects this.

All I know about it:

Creates a RESTORE folder in the root folder

Creates a sub folder which will look like a Recycle Bin

Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe

Creates an autorun.inf with the following:

[autorun]
open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\default=1

A google results gave no results. 18 hours ago there is one result:

http://www.google.com.au/search?q=Taquito....lient=firefox-a

s1521148247650116444919xp5.th.png

Thanks,

McoreD

I tried a search for this string "S-1-5-21-1482476501-1644491937-682003330-1013" and google came up with this. Trendmicro has a reference to WORM_IRCBOT.AQ, so this might be a variant of it.

Link to comment
Share on other sites

  • 0

Thanks - I still have the file.

Only the following AVs detected it:

AntiVir - - HEUR/Crypted

Authentium - - W32/Heuristic-210!Eldorado

CAT-QuickHeal - - (Suspicious) - DNAScan

eSafe - - Suspicious File

F-Prot - - W32/Heuristic-210!Eldorado

NOD32 - - Win32/AutoRun.ABZ

Norman - - W32/Malware.EBZP

Panda - - Suspicious file

Prevx1 - - Worm

SecureWeb-Gateway - - Heuristic.Crypted

Sunbelt - - VIPRE.Suspicious

TrendMicro - - PAK_Generic.001

I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it.

May be time to replace AV. I thought SEP was one of the best AVs out there.

Link to comment
Share on other sites

  • 0
Thanks - I still have the file.

Only the following AVs detected it:

AntiVir - - HEUR/Crypted

Authentium - - W32/Heuristic-210!Eldorado

CAT-QuickHeal - - (Suspicious) - DNAScan

eSafe - - Suspicious File

F-Prot - - W32/Heuristic-210!Eldorado

NOD32 - - Win32/AutoRun.ABZ

Norman - - W32/Malware.EBZP

Panda - - Suspicious file

Prevx1 - - Worm

SecureWeb-Gateway - - Heuristic.Crypted

Sunbelt - - VIPRE.Suspicious

TrendMicro - - PAK_Generic.001

I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it.

May be time to replace AV. I thought SEP was one of the best AVs out there.

NOD32 or KAV are the best.

If it spreads by itself it's certainly malicious, and you want to get rid of it, regardless of what it actually is.

Link to comment
Share on other sites

  • 0

Do NOT replace your AV because of one file. Maybe next week youll find another file that Symantec detects but your new AV doesnt.

Remember that no AV is perfect.

Link to comment
Share on other sites

  • 0
Do NOT replace your AV because of one file. Maybe next week youll find another file that Symantec detects but your new AV doesnt.

Remember that no AV is perfect.

He does have a point.

Link to comment
Share on other sites

  • 0
I have never seen a virus that works on vista up until now. :blink:

Virii will work but only if you let them, this is no acception... if you let it work it will, if you use UAC and take preventative steps this won't be an issue.

Link to comment
Share on other sites

  • 0
I have never seen a virus that works on vista up until now. :blink:

the have hard time getting in with all security built-in

viruses need compatibility update to work in vista of which MS refuse to offer ;)

uac at work ...

Link to comment
Share on other sites

  • 0
i wonder what it does to your system other than folder creation...

It didn't do anything to my system folders because I am running Vista as a Limited User. It would have been successful in XP with Administrator rights but I used to run XP as Limited User too (but it was more troublesome than in Vista). :)

Link to comment
Share on other sites

  • 0

Thankfully most malware authors are still programming for Windows 95. As long as this is the case, Limited User Accounts do a pretty good job of preventing system infection. I'm still running Windows XP (Have always run LUA) and still am amazed at how many programs still require being run as administrator. True, that's what that right click "Run As..." menu item is for, but for shame! If you aren't installing, there's no reason. Needing Power User or below means your programmers still are in the Windows 3.0 world.

Link to comment
Share on other sites

  • 0
Do NOT replace your AV because of one file. Maybe next week youll find another file that Symantec detects but your new AV doesnt.

Remember that no AV is perfect.

+1

yeah..agree with that.

Link to comment
Share on other sites

  • 0
Taquito? now viruses are coming from mexico or something LOL?

Its an illegal immigrant looking for better employment opportunities! :p

Seriously, whatever it is, it sounds bad; I say deep-six it pronto. ;)

Link to comment
Share on other sites

  • 0

You should try Hijack This. It scans your processes and then you can submit the log to their site and it gives you a breakdown of trusted, questionable, and known intruders. That'd probably get tagged in the log scan.

Link to comment
Share on other sites

  • 0
You should try Hijack This. It scans your processes and then you can submit the log to their site and it gives you a breakdown of trusted, questionable, and known intruders. That'd probably get tagged in the log scan.

Right... we already know this is a malicious file...

Link to comment
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.