• 0

Taquito.exe - What is it?


Question

Hi All,

Have you guys heard of this file?

No AntiVirus software I know detects this.

All I know about it:

Creates a RESTORE folder in the root folder

Creates a sub folder which will look like a Recycle Bin

Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe

Creates an autorun.inf with the following:

[autorun]
open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\default=1

A google results gave no results. 18 hours ago there is one result:

http://www.google.com.au/search?q=Taquito....lient=firefox-a

s1521148247650116444919xp5.th.png

Thanks,

McoreD

Link to comment
https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/
Share on other sites

25 answers to this question

Recommended Posts

  • 0
Hi All,

Have you guys heard of this file?

No AntiVirus software I know detects this.

All I know about it:

Creates a RESTORE folder in the root folder

Creates a sub folder which will look like a Recycle Bin

Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe

Creates an autorun.inf with the following:

[autorun]
open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\default=1

A google results gave no results. 18 hours ago there is one result:

http://www.google.com.au/search?q=Taquito....lient=firefox-a

s1521148247650116444919xp5.th.png

Thanks,

McoreD

I tried a search for this string "S-1-5-21-1482476501-1644491937-682003330-1013" and google came up with this. Trendmicro has a reference to WORM_IRCBOT.AQ, so this might be a variant of it.

  • 0

Thanks - I still have the file.

Only the following AVs detected it:

AntiVir - - HEUR/Crypted

Authentium - - W32/Heuristic-210!Eldorado

CAT-QuickHeal - - (Suspicious) - DNAScan

eSafe - - Suspicious File

F-Prot - - W32/Heuristic-210!Eldorado

NOD32 - - Win32/AutoRun.ABZ

Norman - - W32/Malware.EBZP

Panda - - Suspicious file

Prevx1 - - Worm

SecureWeb-Gateway - - Heuristic.Crypted

Sunbelt - - VIPRE.Suspicious

TrendMicro - - PAK_Generic.001

I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it.

May be time to replace AV. I thought SEP was one of the best AVs out there.

  • 0
Thanks - I still have the file.

Only the following AVs detected it:

AntiVir - - HEUR/Crypted

Authentium - - W32/Heuristic-210!Eldorado

CAT-QuickHeal - - (Suspicious) - DNAScan

eSafe - - Suspicious File

F-Prot - - W32/Heuristic-210!Eldorado

NOD32 - - Win32/AutoRun.ABZ

Norman - - W32/Malware.EBZP

Panda - - Suspicious file

Prevx1 - - Worm

SecureWeb-Gateway - - Heuristic.Crypted

Sunbelt - - VIPRE.Suspicious

TrendMicro - - PAK_Generic.001

I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it.

May be time to replace AV. I thought SEP was one of the best AVs out there.

NOD32 or KAV are the best.

If it spreads by itself it's certainly malicious, and you want to get rid of it, regardless of what it actually is.

  • 0
i wonder what it does to your system other than folder creation...

It didn't do anything to my system folders because I am running Vista as a Limited User. It would have been successful in XP with Administrator rights but I used to run XP as Limited User too (but it was more troublesome than in Vista). :)

  • 0

Thankfully most malware authors are still programming for Windows 95. As long as this is the case, Limited User Accounts do a pretty good job of preventing system infection. I'm still running Windows XP (Have always run LUA) and still am amazed at how many programs still require being run as administrator. True, that's what that right click "Run As..." menu item is for, but for shame! If you aren't installing, there's no reason. Needing Power User or below means your programmers still are in the Windows 3.0 world.

  • 0
You should try Hijack This. It scans your processes and then you can submit the log to their site and it gives you a breakdown of trusted, questionable, and known intruders. That'd probably get tagged in the log scan.

Right... we already know this is a malicious file...

  • 0

Hi there,

I know how to stop Taquito.EXE from functioning, without endangering you restore files.

The details are on my website, Virus Alert!, and the program you need is linked to. The URL is:

http://virusalert.weebly.com/t.html

Hope this helps. Worked for me.

Taquito.EXE is a worm, by the way.

:spam:

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Honestly that feels even more useless than it did when Win11 was first released. In 2021, the uproar was somewhat justified, but only when comparing how good we've had it since Windows 7. Prior to that, a new Windows release would often require new, or very recent hardware. Windows XP wouldn't run (in any usable way) on hardware released when it's predecessor Win98 was released (let's ignore ME). It was time to shift the goal post, and the way Microsoft did that was actually ok. People have still had another FIVE YEARS of free software support with Windows 10, and those of us who want to have used these tools to bypass the limitations, all while understanding the impacts that may have. Most laptops don't last 5 years (sadly), so now the youngest unsupported hardware is 9 years old, and apparently has another year of support with Windows 10. That's good. Meanwhile, understanding the impacts and limitations, I have my 2013 laptop running Win11 perfectly fine. The thing that's failing on it is the hardware, the 2.5" SATA cable/chip is failing and corrupting the SSDs I put in. Thankfully it has a functional M.2 sata drive that works fine!
    • iPhone 18 Pro drop-test video and photos leak on the dark web following a data breach by Hamid Ganji iPhone 17 Pro - Image via Apple Apple is seemingly facing one of the biggest data breaches in its history, and just a few months before the official debut of the iPhone 18 Pro series, photos, a drop-test video, a supplier list, and key phone components have reportedly been leaked by hackers. Last week, we reported that Tata Electronics, an Apple supplier and iPhone producer in India, was hit by a data breach. As a result, it was reported that more than 200,000 trade secrets and confidential documents belonging to Apple and Tesla were stolen by the ransomware group World Leaks. According to Reuters, the group has now leaked supplier lists, component details, and photos of the upcoming iPhone 18 Pro models on the dark web. One of the materials leaked by the hackers is a drop-test video of the iPhone 18 Pro, which is due to launch this September. The phone is shown in a gray color and has the same familiar design we saw on last year's iPhone 17 Pro series. The device also appears to be quite durable, though it seems to be thicker than last year's model. One possible explanation is that Apple may be using a larger battery in the iPhone 18 Pro series. Moreover, Reuters says it has seen at least six documents mapping many components in the iPhone 18 Pro models to their respective suppliers, including details on chips on the main circuit board and on battery and camera components. The documents reportedly detail hundreds of parts that will be used in the iPhone 18 Pro models. A person familiar with the matter told the outlet that Apple classifies this data as sensitive and “is concerned about the documents being shared on the dark web as they relate to unreleased models.” Apple is reportedly investigating the issue but has yet to issue an official statement.
    • You do you, I've just said that it first appeared in "home" version before it will be available in "work" one. I use Edge only because it still supports MV2 uBO extension even on Android - I'll switch when they stop.
    • I imagine that was a review or something? My reviews mostly contain a lot of images and galleries, but these are all webp too, but yeah it all adds up on the page load. Would help if you were more helpful with your critique instead of bitching and moaning like a Karen 😂 Because then we might be able to fix it for you.
    • If Valve refused to let them make the case, I wonder if they've already partnered with someone else to do it? The fact that they didn't seek permission/licence before diving straight in is incredible though
  • Recent Achievements

    • First Post
      rosiecharles earned a badge
      First Post
    • Reacting Well
      Juan Dela earned a badge
      Reacting Well
    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      516
    2. 2
      +Edouard
      273
    3. 3
      PsYcHoKiLLa
      142
    4. 4
      Steven P.
      100
    5. 5
      macoman
      53
  • Tell a friend

    Love Neowin? Tell a friend!