• 0

Taquito.exe - What is it?


Question

Hi All,

Have you guys heard of this file?

No AntiVirus software I know detects this.

All I know about it:

Creates a RESTORE folder in the root folder

Creates a sub folder which will look like a Recycle Bin

Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe

Creates an autorun.inf with the following:

[autorun]
open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\default=1

A google results gave no results. 18 hours ago there is one result:

http://www.google.com.au/search?q=Taquito....lient=firefox-a

s1521148247650116444919xp5.th.png

Thanks,

McoreD

Link to comment
https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/
Share on other sites

25 answers to this question

Recommended Posts

  • 0
Hi All,

Have you guys heard of this file?

No AntiVirus software I know detects this.

All I know about it:

Creates a RESTORE folder in the root folder

Creates a sub folder which will look like a Recycle Bin

Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe

Creates an autorun.inf with the following:

[autorun]
open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\default=1

A google results gave no results. 18 hours ago there is one result:

http://www.google.com.au/search?q=Taquito....lient=firefox-a

s1521148247650116444919xp5.th.png

Thanks,

McoreD

I tried a search for this string "S-1-5-21-1482476501-1644491937-682003330-1013" and google came up with this. Trendmicro has a reference to WORM_IRCBOT.AQ, so this might be a variant of it.

  • 0

Thanks - I still have the file.

Only the following AVs detected it:

AntiVir - - HEUR/Crypted

Authentium - - W32/Heuristic-210!Eldorado

CAT-QuickHeal - - (Suspicious) - DNAScan

eSafe - - Suspicious File

F-Prot - - W32/Heuristic-210!Eldorado

NOD32 - - Win32/AutoRun.ABZ

Norman - - W32/Malware.EBZP

Panda - - Suspicious file

Prevx1 - - Worm

SecureWeb-Gateway - - Heuristic.Crypted

Sunbelt - - VIPRE.Suspicious

TrendMicro - - PAK_Generic.001

I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it.

May be time to replace AV. I thought SEP was one of the best AVs out there.

  • 0
Thanks - I still have the file.

Only the following AVs detected it:

AntiVir - - HEUR/Crypted

Authentium - - W32/Heuristic-210!Eldorado

CAT-QuickHeal - - (Suspicious) - DNAScan

eSafe - - Suspicious File

F-Prot - - W32/Heuristic-210!Eldorado

NOD32 - - Win32/AutoRun.ABZ

Norman - - W32/Malware.EBZP

Panda - - Suspicious file

Prevx1 - - Worm

SecureWeb-Gateway - - Heuristic.Crypted

Sunbelt - - VIPRE.Suspicious

TrendMicro - - PAK_Generic.001

I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it.

May be time to replace AV. I thought SEP was one of the best AVs out there.

NOD32 or KAV are the best.

If it spreads by itself it's certainly malicious, and you want to get rid of it, regardless of what it actually is.

  • 0
i wonder what it does to your system other than folder creation...

It didn't do anything to my system folders because I am running Vista as a Limited User. It would have been successful in XP with Administrator rights but I used to run XP as Limited User too (but it was more troublesome than in Vista). :)

  • 0

Thankfully most malware authors are still programming for Windows 95. As long as this is the case, Limited User Accounts do a pretty good job of preventing system infection. I'm still running Windows XP (Have always run LUA) and still am amazed at how many programs still require being run as administrator. True, that's what that right click "Run As..." menu item is for, but for shame! If you aren't installing, there's no reason. Needing Power User or below means your programmers still are in the Windows 3.0 world.

  • 0
You should try Hijack This. It scans your processes and then you can submit the log to their site and it gives you a breakdown of trusted, questionable, and known intruders. That'd probably get tagged in the log scan.

Right... we already know this is a malicious file...

  • 0

Hi there,

I know how to stop Taquito.EXE from functioning, without endangering you restore files.

The details are on my website, Virus Alert!, and the program you need is linked to. The URL is:

http://virusalert.weebly.com/t.html

Hope this helps. Worked for me.

Taquito.EXE is a worm, by the way.

:spam:

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I'm still rocking iOS 25.x on my primary phone cuz iOS 26 still has usability quirks (mostly aesthetic and thus its UX) which I don't wanna deal with -- and I've been piloting them with all of these updates on my backup phone, so I'm well aware of its "improvements" since iOS 26 was first released (compared to version 26.5.x).
    • Firefox 152.0.4 is out.
    • Then why are you still here?  
    • Glary Utilities 6.44.0.48 by Razvan Serea Glary Utilities offers numerous powerful and easy-to-use system tools and utilities to fix, speed up, maintain and protect your PC. Glary Utilities allow you to clean common system junk files, as well as invalid registry entries and Internet traces. You can manage and delete browser add-ons, analyze disk space usage and find duplicate files. You can also view and manage installed shell extensions, encrypt your files from unauthorized access and use, split large files into smaller manageable files and then rejoin them. Furthermore, Glary Utilities includes the options to find, fix, or remove broken Windows shortcuts, manage the programs that start at Windows startup and uninstall software. All Glary Utilities tools can be accessed through an eye-pleasing and totally simplistic interface. Glary Utilities 6.44.0.48 changelog: Optimized Context Menu Manager: Improved features based on user feedback. Optimized Wipe Free Space: Optimized the interface display for a better user experience. Minor GUI improvements. Minor bug fixes. Download: Glary Utilities 6.44.0.48 | 27.0 MB (Freeware) Download: Portable Glary Utilities | 32.3 MB View: Glary Utilities Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • why to touch this audio corpse? use aimp
  • Recent Achievements

    • Reacting Well
      Juan Dela earned a badge
      Reacting Well
    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      514
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      146
    4. 4
      Steven P.
      96
    5. 5
      macoman
      54
  • Tell a friend

    Love Neowin? Tell a friend!