Malware

Win32/AutoRun.Agent.PU removal tips

Malware Removal

The Win32/AutoRun.Agent.PU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.Agent.PU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.Agent.PU?


File Info:

name: 04D06D1A5025C5606A3C.mlw
path: /opt/CAPEv2/storage/binaries/c5d156ae6444feab82608b356e9a607b9017731f74f1755c645a3ffe57410c88
crc32: 786370F1
md5: 04d06d1a5025c5606a3c10bd3bdf7688
sha1: 97d6cb6f927383f96e3c0dc7f6819102b44b8b2f
sha256: c5d156ae6444feab82608b356e9a607b9017731f74f1755c645a3ffe57410c88
sha512: b7195def19b6d9dd2e65ad949242250f3306a04e6e3bae032d68cb7126519a0ebe1950184e686a3607708dbbccfa99785479b5bf0c4e3efedc8693414db3a829
ssdeep: 384:PAZCt+T/poPfolJ/89Ma1A4bBGGUoyuqDEHVlB29DsN5Pu:IZCgTwul+Maa4VGGU4GE3aDuk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DD2BFBF2918CDE7D693677614BD1D0182FA93440265584EB82EDFC86D6F0C20E3A6A6
sha3_384: d8aa1a9b30a8b416ec7aec04dd00af0065410d9084fca7313a68e6064ed7a9cff8fca2c6f3e4f6af54f03d469120528e
ep_bytes: 890d85684000ba200000008905486a40
timestamp: 2006-11-17 03:08:00

Version Info:

0: [No Data]

Win32/AutoRun.Agent.PU also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Mondera.3!c
DrWebTrojan.Packed.1190
MicroWorld-eScanMemScan:Trojan.Downloader.Agent.ZTU
FireEyeGeneric.mg.04d06d1a5025c560
ALYacMemScan:Trojan.Downloader.Agent.ZTU
MalwarebytesMachineLearning/Anomalous.100%
VIPREMemScan:Trojan.Downloader.Agent.ZTU
SangforSuspicious.Win32.Save.a
AlibabaPacked:Win32/Mondera.26247797
K7GWTrojan ( 700001211 )
Cybereasonmalicious.a5025c
BitDefenderThetaAI:Packer.0C1F58A11E
CyrenW32/Downloader_Small.B!Gen
SymantecW32.SillyDC
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.Agent.PU
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Mondera.e
BitDefenderMemScan:Trojan.Downloader.Agent.ZTU
NANO-AntivirusTrojan.Win32.Mondera.fptckw
AvastWin32:Fabot [Trj]
TencentWin32.Packed.Mondera.Zylw
EmsisoftMemScan:Trojan.Downloader.Agent.ZTU (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Worm.Autorun.bo
ZillyaWorm.AutoRun.Win32.140406
TrendMicroWORM_ALUREON.DEN
McAfee-GW-EditionDNSChanger.ac
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-IQ
SentinelOneStatic AI – Malicious PE
GDataMemScan:Trojan.Downloader.Agent.ZTU
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
XcitiumPacked.Win32.Mondera.~e@2octcv
ArcabitTrojan.Downloader.Agent.ZTU
ZoneAlarmPacked.Win32.Mondera.e
MicrosoftTrojan:Win32/Alureon.gen!J
GoogleDetected
AhnLab-V3Worm/Win32.AutoRun.C74502
McAfeeDNSChanger.ac
VBA32BScope.Trojan.Packed
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_ALUREON.DEN
RisingTrojan.Generic@AI.100 (RDML:pMsnxYuC/O+52TGUjmGBNA)
IkarusTrojan.Win32.Alureon
MaxSecureTrojan.Malware.590015.susgen
FortinetW32/Alureon.fam!tr
AVGWin32:Fabot [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/AutoRun.Agent.PU?

Win32/AutoRun.Agent.PU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment