McoreD Posted October 19, 2008 Share Posted October 19, 2008 Hi All, Have you guys heard of this file? No AntiVirus software I know detects this. All I know about it: Creates a RESTORE folder in the root folder Creates a sub folder which will look like a Recycle Bin Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe Creates an autorun.inf with the following: [autorun] open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe icon=%SystemRoot%\system32\SHELL32.dll,4 action=Open folder to view files shell\open=Open shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe shell\open\default=1 A google results gave no results. 18 hours ago there is one result: http://www.google.com.au/search?q=Taquito....lient=firefox-a Thanks, McoreD Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/ Share on other sites More sharing options...
0 Yusuf M. Veteran Posted October 19, 2008 Veteran Share Posted October 19, 2008 Nope, never heard of it. I can't find anything about it on the net either. It must be some kind of worm if it does what you mentioned. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589990454 Share on other sites More sharing options...
0 +Thom Vee Subscriber² Posted October 19, 2008 Subscriber² Share Posted October 19, 2008 Hi All, Have you guys heard of this file? No AntiVirus software I know detects this. All I know about it: Creates a RESTORE folder in the root folder Creates a sub folder which will look like a Recycle Bin Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe Creates an autorun.inf with the following: [autorun] open=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe icon=%SystemRoot%\system32\SHELL32.dll,4 action=Open folder to view files shell\open=Open shell\open\command=RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe shell\open\default=1 A google results gave no results. 18 hours ago there is one result: http://www.google.com.au/search?q=Taquito....lient=firefox-a Thanks, McoreD I tried a search for this string "S-1-5-21-1482476501-1644491937-682003330-1013" and google came up with this. Trendmicro has a reference to WORM_IRCBOT.AQ, so this might be a variant of it. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589990456 Share on other sites More sharing options...
0 fatboyuk Posted October 19, 2008 Share Posted October 19, 2008 If you still have the file, try uploading it to http://www.virustotal.com/ - that checks it with a load of AV products. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589990486 Share on other sites More sharing options...
0 McoreD Posted October 19, 2008 Author Share Posted October 19, 2008 Thanks - I still have the file. Only the following AVs detected it: AntiVir - - HEUR/Crypted Authentium - - W32/Heuristic-210!Eldorado CAT-QuickHeal - - (Suspicious) - DNAScan eSafe - - Suspicious File F-Prot - - W32/Heuristic-210!Eldorado NOD32 - - Win32/AutoRun.ABZ Norman - - W32/Malware.EBZP Panda - - Suspicious file Prevx1 - - Worm SecureWeb-Gateway - - Heuristic.Crypted Sunbelt - - VIPRE.Suspicious TrendMicro - - PAK_Generic.001 I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it. May be time to replace AV. I thought SEP was one of the best AVs out there. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589990574 Share on other sites More sharing options...
0 primexx Posted October 19, 2008 Share Posted October 19, 2008 Thanks - I still have the file. Only the following AVs detected it: AntiVir - - HEUR/Crypted Authentium - - W32/Heuristic-210!Eldorado CAT-QuickHeal - - (Suspicious) - DNAScan eSafe - - Suspicious File F-Prot - - W32/Heuristic-210!Eldorado NOD32 - - Win32/AutoRun.ABZ Norman - - W32/Malware.EBZP Panda - - Suspicious file Prevx1 - - Worm SecureWeb-Gateway - - Heuristic.Crypted Sunbelt - - VIPRE.Suspicious TrendMicro - - PAK_Generic.001 I was using Symantec EndPoint Protection (AntiVirus 11) and it couldn't detect it. May be time to replace AV. I thought SEP was one of the best AVs out there. NOD32 or KAV are the best. If it spreads by itself it's certainly malicious, and you want to get rid of it, regardless of what it actually is. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589993524 Share on other sites More sharing options...
0 anonymous_user Posted October 20, 2008 Share Posted October 20, 2008 Do NOT replace your AV because of one file. Maybe next week youll find another file that Symantec detects but your new AV doesnt. Remember that no AV is perfect. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589993670 Share on other sites More sharing options...
0 Argote Posted October 20, 2008 Share Posted October 20, 2008 Do NOT replace your AV because of one file. Maybe next week youll find another file that Symantec detects but your new AV doesnt.Remember that no AV is perfect. He does have a point. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589993694 Share on other sites More sharing options...
0 Kami- Posted October 20, 2008 Share Posted October 20, 2008 What is it? Well... quite simply, a worm. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589995488 Share on other sites More sharing options...
0 Malskazz Posted October 20, 2008 Share Posted October 20, 2008 What is it?Well... quite simply, a worm. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589995518 Share on other sites More sharing options...
0 Snakehn Posted October 20, 2008 Share Posted October 20, 2008 Taquito? now viruses are coming from mexico or something LOL? Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589995536 Share on other sites More sharing options...
0 deep1234 Posted October 20, 2008 Share Posted October 20, 2008 I have never seen a virus that works on vista up until now. :blink: Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589996212 Share on other sites More sharing options...
0 _BeanZ_ Posted October 20, 2008 Share Posted October 20, 2008 Taquito? now viruses are coming from mexico or something LOL? I've seen burrito.exe before - maybe someone's working there way through the menu. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589996752 Share on other sites More sharing options...
0 Kami- Posted October 20, 2008 Share Posted October 20, 2008 I have never seen a virus that works on vista up until now. :blink: Virii will work but only if you let them, this is no acception... if you let it work it will, if you use UAC and take preventative steps this won't be an issue. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589996772 Share on other sites More sharing options...
0 fatboyuk Posted October 20, 2008 Share Posted October 20, 2008 I have never seen a virus that works on vista up until now. :blink: I have never seen anything work on vista, full stop ;) Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589996818 Share on other sites More sharing options...
0 freeza Posted October 20, 2008 Share Posted October 20, 2008 i wonder what it does to your system other than folder creation... Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589996820 Share on other sites More sharing options...
0 Ci7 Posted October 20, 2008 Share Posted October 20, 2008 I have never seen a virus that works on vista up until now. :blink: the have hard time getting in with all security built-in viruses need compatibility update to work in vista of which MS refuse to offer ;) uac at work ... Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589996852 Share on other sites More sharing options...
0 McoreD Posted October 20, 2008 Author Share Posted October 20, 2008 i wonder what it does to your system other than folder creation... It didn't do anything to my system folders because I am running Vista as a Limited User. It would have been successful in XP with Administrator rights but I used to run XP as Limited User too (but it was more troublesome than in Vista). :) Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-589998676 Share on other sites More sharing options...
0 gollux Posted October 21, 2008 Share Posted October 21, 2008 Thankfully most malware authors are still programming for Windows 95. As long as this is the case, Limited User Accounts do a pretty good job of preventing system infection. I'm still running Windows XP (Have always run LUA) and still am amazed at how many programs still require being run as administrator. True, that's what that right click "Run As..." menu item is for, but for shame! If you aren't installing, there's no reason. Needing Power User or below means your programmers still are in the Windows 3.0 world. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590002070 Share on other sites More sharing options...
0 anonymous_user Posted October 23, 2008 Share Posted October 23, 2008 ^ Actually I think most malware writers stopped targetting Win9x. They want to go after the majority of users (XP/Vista) dont they? Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590008720 Share on other sites More sharing options...
0 kjordan2001 Posted October 23, 2008 Share Posted October 23, 2008 I've seen burrito.exe before - maybe someone's working there way through the menu. Let me know when they get to tequila.exe, then it'll have a true worm ;) Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590008748 Share on other sites More sharing options...
0 darren89 Posted October 27, 2008 Share Posted October 27, 2008 Do NOT replace your AV because of one file. Maybe next week youll find another file that Symantec detects but your new AV doesnt.Remember that no AV is perfect. +1 yeah..agree with that. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590027214 Share on other sites More sharing options...
0 ScorpioRGc1 Posted October 27, 2008 Share Posted October 27, 2008 Taquito? now viruses are coming from mexico or something LOL? Its an illegal immigrant looking for better employment opportunities! :p Seriously, whatever it is, it sounds bad; I say deep-six it pronto. ;) Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590027282 Share on other sites More sharing options...
0 ninjamunky Posted October 27, 2008 Share Posted October 27, 2008 You should try Hijack This. It scans your processes and then you can submit the log to their site and it gives you a breakdown of trusted, questionable, and known intruders. That'd probably get tagged in the log scan. Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590027306 Share on other sites More sharing options...
0 Kami- Posted October 27, 2008 Share Posted October 27, 2008 You should try Hijack This. It scans your processes and then you can submit the log to their site and it gives you a breakdown of trusted, questionable, and known intruders. That'd probably get tagged in the log scan. Right... we already know this is a malicious file... Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590028734 Share on other sites More sharing options...
0 microchip092 Posted January 6, 2009 Share Posted January 6, 2009 Hi there, I know how to stop Taquito.EXE from functioning, without endangering you restore files. The details are on my website, Virus Alert!, and the program you need is linked to. The URL is: http://virusalert.weebly.com/t.html Hope this helps. Worked for me. Taquito.EXE is a worm, by the way. :spam: Link to comment https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/#findComment-590374310 Share on other sites More sharing options...
Question
McoreD
Hi All,
Have you guys heard of this file?
No AntiVirus software I know detects this.
All I know about it:
Creates a RESTORE folder in the root folder
Creates a sub folder which will look like a Recycle Bin
Inside the folder S-1-5-21-1482476501-1644491937-682003330-1013 there is Taquito.exe
Creates an autorun.inf with the following:
A google results gave no results. 18 hours ago there is one result:
http://www.google.com.au/search?q=Taquito....lient=firefox-a
Thanks,
McoreD
Link to comment
https://www.neowin.net/forum/topic/684430-taquitoexe-what-is-it/Share on other sites
25 answers to this question
Recommended Posts