Worm

How to remove “Generic.Worm.AutoRun.DDS”?

Malware Removal

The Generic.Worm.AutoRun.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Worm.AutoRun.DDS virus can do?

  • Unconventionial language used in binary resources: Arabic
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Generic.Worm.AutoRun.DDS?


File Info:

name: 1E009DE4F9B0515CA7B8.mlw
path: /opt/CAPEv2/storage/binaries/e5394cdd82f72f1bc13e0d24f4e8d7939aa3299c6805f622064e9965902fbb39
crc32: 76F312D4
md5: 1e009de4f9b0515ca7b856a4a38c8dee
sha1: cef71f78da37dfdfc4dc432531fd0e052682ba3c
sha256: e5394cdd82f72f1bc13e0d24f4e8d7939aa3299c6805f622064e9965902fbb39
sha512: 1f2374afa50731206b65bcb7bf55dd37835d4cb96c93b3b94e4ec121ffc889131158dd530fc304e469196cff94b296ec24338b0f461d3a369ea6daa958537e72
ssdeep: 1536:ipHuQ12DL57bqhb+lauaiqmPMxNWETBfxzSCel8uWZHNInjrIr7rVr2QrOi/:iN2DUhb+lauRGBM8VsrIr7rVrprO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165B32919F7150495D81C707177878FA344A3B41ADAAF11C1339923EABD3AE52463DB2F
sha3_384: 100d48e720c9313c42be86fbb17980876ad3bdc2e7611dfb5bf21cbec1a22ec0a16c4f8682370148285662b16fcfdce2
ep_bytes: 60be00f043008dbe0020fcff5783cdff
timestamp: 2011-02-05 01:35:21

Version Info:

0: [No Data]

Generic.Worm.AutoRun.DDS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.1e009de4f9b0515c
McAfeeArtemis!1E009DE4F9B0
CylanceUnsafe
VIPREGen:Trojan.Heur.hmW@!hDs@JcG
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.4f9b05
BaiduWin32.Worm.Agent.y
CyrenW32/S-3128c29c!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Packed.Shakblades-9811684-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.hmW@!hDs@JcG
MicroWorld-eScanGen:Trojan.Heur.hmW@!hDs@JcG
AvastWin32:AutoIt-BYV [Trj]
Ad-AwareGen:Trojan.Heur.hmW@!hDs@JcG
EmsisoftGen:Trojan.Heur.hmW@!hDs@JcG (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Generic.Win32.1659401
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.hmW@!hDs@JcG
JiangminTrojan.Generic.hkxzc
AviraTR/Crypt.ULPM.Gen
ArcabitTrojan.Heur.EBEE08
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Seint.R497883
Acronissuspicious
BitDefenderThetaAI:Packer.3C024A501C
ALYacGen:Trojan.Heur.hmW@!hDs@JcG
MAXmalware (ai score=87)
MalwarebytesGeneric.Worm.AutoRun.DDS
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:AutoIt-BYV [Trj]

How to remove Generic.Worm.AutoRun.DDS?

Generic.Worm.AutoRun.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment