Malware

How to remove “VirTool:Win32/AutoRun!atmn”?

Malware Removal

The VirTool:Win32/AutoRun!atmn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/AutoRun!atmn virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine VirTool:Win32/AutoRun!atmn?


File Info:

crc32: AA815005
md5: dd2a599cdf0afe66a8c281e3bf6e5617
name: DD2A599CDF0AFE66A8C281E3BF6E5617.mlw
sha1: 93ffa4b1d414f1750ff0fefdec3cb22707909446
sha256: 4c4d7e77d77b651d4c3494213991ce6ff2c8f72767965a8959a9804e90aa8d56
sha512: e1b9f49b76cc2eb39c1c724c9cf245e41dabfab4fadd197c2d3b7b80837636aded9ba3d6d58be276c803908560b3cb8b04ed7afdaa73aa1f0968250f390d50c3
ssdeep: 49152:s6VSwjUb2GBle6FXB6IJZZMQzj2xs6bSbpQXYV/j/ufzPCi45DCg5gRmep89:rVtjUjleLIhMKCxn0sGrarCiuugmRB89
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 x4e50x8d4f 1998-2022
InternalName: Setup.exe
FileVersion: 1,2,0,8
CompanyName: x67cfx6797x4e4bx5730xff08GBT_Setup&toolsxff09
PrivateBuild: x2018 WORLD ORDER
LegalTrademarks: China.tianchao
Comments: x672cx7a0bx5e8fx7531x67cfx6797x4e4bx5730xff08GBT_Setup&toolsxff09,x4efbx4f55x4ebax4e0dx5f97x7528x4e8ex6728x9a6c,x75c5x6bd2,x540ex95e8x7b49x7528x9014!x7531x6b64x9020x6210x4e00x5207x540ex679c,x672cx4ebax4e0dx8d1fx4efbx4f55x53cax8fdex5e26x8d23x4efb!
ProductName: x4e16x754c
SpecialBuild: x4e0dx5728x7b49x5f85
ProductVersion: 1.2.0.8
FileDescription: x67cfx6797x4e4bx5730xff08GBT_Setup&toolsxff09
OriginalFilename: Setup.exe
Translation: 0x0804 0x04b0

VirTool:Win32/AutoRun!atmn also known as:

K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
ClamAVWin.Malware.Zusy-9865601-0
CAT-QuickHealTrojan.GenericIH.S19283219
ALYacGen:Variant.Zusy.333040
CylanceUnsafe
ZillyaTrojan.Bsymem.Win32.1771
BitDefenderGen:Variant.Zusy.333040
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.cdf0af
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Bsymem.gen
NANO-AntivirusTrojan.Win32.Redcap.iaszqe
MicroWorld-eScanGen:Variant.Zusy.333040
Ad-AwareGen:Variant.Zusy.333040
SophosGeneric ML PUA (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34266.@t3@aa0lgnab
FireEyeGeneric.mg.dd2a599cdf0afe66
EmsisoftGen:Variant.Zusy.333040 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Bsymem.agm
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2D1AC8E
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/AutoRun!atmn
GDataWin32.Trojan.PSE.12FI8JT
AhnLab-V3Malware/Win32.RL_Generic.R358180
Acronissuspicious
McAfeeGenericRXAA-AA!DD2A599CDF0A
MAXmalware (ai score=87)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
YandexTrojan.GenAsa!oW8qKXH2CnE
IkarusPUA.BlackMoon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr

How to remove VirTool:Win32/AutoRun!atmn?

VirTool:Win32/AutoRun!atmn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment