Skypee and AutoIt3.exe, What it really is?

Discussion in 'Windows 10' started by pisthai, Jul 26, 2022.

  1. pisthai

    pisthai Imperfect Human

    Jul 29, 2009
    7,202
    2,269
    240
    Skypee and AutoIt3.exe, What are they really?

    The last few days I was getting some problems with Windows 10 Pro, special with Skypee and AutoIt3.exe! They created hidden Directories on the root of Drive C as well as a lot of .lnk files on many places of the HDDs!

    Are those files etc dangerous by any means?

    Googling did not really bring a good explanation! What are the experiences or so of MDLer?

    Please keep answers on the topic and refrain from not related issues! Thanks.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. pisthai

    pisthai Imperfect Human

    Jul 29, 2009
    7,202
    2,269
    240
    I just found out that on my Laptop (Acer Aspire 4752G) I got the same problem on Windows 11 Pro!
    In both hidden directories Google and Skypee on the root of the C Drive are the same 2 shortcuts: GoogleUpdate and Windowsupdate! And hundreds of .lnk links are now all over the HDD!

    Checked some of those .lnk files. they're classified as Trojans etc.!

    So, what the he** is going on here?

    Thanks for any useful answer.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. pisthai

    pisthai Imperfect Human

    Jul 29, 2009
    7,202
    2,269
    240
    On the Windows 10 Pro machine, I've the HDDs free again> That really was a hard job to do and I do not know that will last! Let's see how it would be?!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. Carlos Detweiller

    Carlos Detweiller Emperor of Ice-Cream

    Dec 21, 2012
    6,777
    7,731
    210
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. pisthai

    pisthai Imperfect Human

    Jul 29, 2009
    7,202
    2,269
    240
    Even using Avast, and a few other AV apps, they didn't delete those .lnk files at all! more than 2870 of them just un the C Drive of the Windows 10 Pro Machine!

    I think I've now only one choice and that is a clean install of Windows 10 Pro again!

    After trying to delete some of that .lnk files, I face now more problems again. Just now I'm saving a few data from today and will LLFMT format the HDD first before installing Windows 10 Pro again.

    Thanks for all answers.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. Carlos Detweiller

    Carlos Detweiller Emperor of Ice-Cream

    Dec 21, 2012
    6,777
    7,731
    210
    Most probably, the AV software will not remove the .lnk files, as it cannot distinguish between the Shortcuts created by users and the others created by the Malware.

    Note that it mimics the names of popular software, like Skype (a communication software) and AutoIt! 3, which is a automation language and by itself totally legit.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. pisthai

    pisthai Imperfect Human

    Jul 29, 2009
    7,202
    2,269
    240
    Even using Avast, and a few other AV apps, they didn't delete those .lnk files at all! more than 2870 of them just un the C Drive of the Windows 10 Pro Machine!

    I'm now reinstalling Windows 10 Pro on the desktop.

    Thanks for all answers.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,556
    15,642
    270
    It's a virus :haha:
     
  9. JBenal

    JBenal MDL Addicted

    Nov 2, 2009
    521
    209
    30
    You don't have a backup?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,556
    15,642
    270
    He doesn't for sure :haha:
     
  11. JBenal

    JBenal MDL Addicted

    Nov 2, 2009
    521
    209
    30
    That's too bad. Use Macrium Reflect Free v8 in the future.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  12. acer-5100

    acer-5100 MDL Guru

    Dec 8, 2018
    4,003
    2,923
    150

    Learn to use native vhds, and forget 1990's backup/imaging sw. 1 copy/paste will be enough.
     
  13. Carlos Detweiller

    Carlos Detweiller Emperor of Ice-Cream

    Dec 21, 2012
    6,777
    7,731
    210
    Again, the AV will (hopefully) remove the Malware itself, but, as it does not know if the Shortcuts were all created by the Malware, it leaves them alone.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. pisthai

    pisthai Imperfect Human

    Jul 29, 2009
    7,202
    2,269
    240
    I do have backups from all of my data, therefore, I didn't lose anything!

    Just because of many changes done nearly every day on that computer, a 'Cloning' really didn't works, a clean install and adding the needed apps, is faster and even more secure! And such re-installing need to be done fully, including at least for the formatting of all Partition of the used HDD because I was trying first just a new install of the C-Partition only (after formatting that partition first!) and the two directories of Google and Skypee were back after the installation was done! Seems to be that they were also placed into that Recovery and Backup Partition (50 and 500 MB in size)! formatted them as well too, and now everything is back to normal

    I'm now letting the system show, not just the Hidden Files and Folders, but also the hidden protected System Files because those 2 Dir's are not shown by using just the show of Hidden Files and Folders!

    Until right now, I didn't know where those infections were coming from! Therefore I'll keep a very close on where they may be come back from!

    Thanks for all answers, except those which did not get a Like!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  15. Carlos Detweiller

    Carlos Detweiller Emperor of Ice-Cream

    Dec 21, 2012
    6,777
    7,731
    210
    Looks like that was a real nasty one... And it's damaging the reputation of real good software like AutoIt! 3, that way. Even some MDL tools are partially written in AutoIt language, and many AVs just tag everything written in AutoIt as virus/Malware. A real shame, makes me sad.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...