aux32.exe - Dangerous
aux32.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
This worm propagates by scanning randomly selected IP addresses for vulnerable systems.
Copies itself as %System%\aux32.exe and adds the value: "auxAudioDevice"="c:\winnt\system32\aux32.exe"
to the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Pings a randomly generated IP address to determine whether a remote computer is online.
If the remote computer appears to be online, the worm connects to it on TCP port 445 and sends shell code to it.
Downloads zu.exe, which is a corrupted Trojan, from 67.19.12.122.
Also, attempts to connect to 67.19.12.122/zuu.php.
Remove this spyware with RegRun Startuip Optimizer.