Malware

Win32:AutoRun-AOY [Wrm] removal tips

Malware Removal

The Win32:AutoRun-AOY [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:AutoRun-AOY [Wrm] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32:AutoRun-AOY [Wrm]?


File Info:

name: 4BEC91D99D365900A2D3.mlw
path: /opt/CAPEv2/storage/binaries/8c0cfe48723192d533dba008d30a06da6361aa318d32d6c720b410865475f2df
crc32: 8A241FAB
md5: 4bec91d99d365900a2d35e294ad927b5
sha1: 43cdd871c3dd53c37048f43f71249ae431a4ad3f
sha256: 8c0cfe48723192d533dba008d30a06da6361aa318d32d6c720b410865475f2df
sha512: fca8a1df0c86b027bc36d9a3fcecb457e1c53052220c4d92160934dc76afe05660815a9792cf83c28213afb6a1e0198fde42577be7bb593060db8b2ba74d8f84
ssdeep: 6144:Wf+Jjjou35J6i5plrzuo6/LkeYvjoIHnv0RX/VwFdLD/7MsrYMC+9GXL9M8sG3dp:hj8u3ui5pl+uBvc/V0FdYxJdRqMF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AA46D32F3F19433D1331A788D5B93AC982ABE113D28A8467BE91D4C5F39791742B297
sha3_384: 565d9d73d8eed294c56d9b07d892656ff8cc160f12a1c294d296e56e51bd557147007da53d610b92eeeb41047738296d
ep_bytes: 558bec83c4f0b850554600e8fc18faff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:AutoRun-AOY [Wrm] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.359768
CAT-QuickHealWorm.Autorun.RE8
ALYacGen:Variant.Zusy.359768
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.550
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005726171 )
K7GWTrojan ( 005726171 )
Cybereasonmalicious.99d365
BitDefenderThetaGen:NN.ZelphiF.34294.DGW@aCpuCyki
CyrenW32/Worm.ALYD
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.Delf.J
BaiduWin32.Worm.Autorun.s
TrendMicro-HouseCallMal_Otorun5
ClamAVWin.Worm.Autorun-314
KasperskyTrojan.Win32.Fsysna.dhqm
BitDefenderGen:Variant.Zusy.359768
NANO-AntivirusTrojan.Win32.AutoRun.dzjjvz
SUPERAntiSpywareTrojan.Agent/Gen-Autorun
AvastWin32:AutoRun-AOY [Wrm]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Zusy.359768
TACHYONWorm/W32.DP-AutoRun.483840
EmsisoftGen:Variant.Zusy.359768 (B)
ComodoWorm.Win32.AutoRun.~ZP@2mkay
DrWebTrojan.Winlock.14301
VIPRETrojan.Win32.Generic!SB.0
TrendMicroMal_Otorun5
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.4bec91d99d365900
SophosML/PE-A + Mal/SillyFDC-A
APEXMalicious
GDataGen:Variant.Zusy.359768
JiangminWorm/AutoRun.dir
WebrootW32.Autorun.Gen
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3F55
KingsoftHeur.SSC.2722881.1216.(kcloud)
ArcabitTrojan.Zusy.D57D58
MicrosoftWorm:Win32/Autorun.RE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AutoRun.C65764
Acronissuspicious
McAfeeW32/Autorun.worm.zi
MAXmalware (ai score=82)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.1856542377
RisingWorm.Autorun!1.9D28 (CLASSIC)
YandexTrojan.GenAsa!l9OHG3irraI
IkarusWorm.Win32.AutoRun
eGambitUnsafe.AI_Score_100%
FortinetW32/Autorun.DJ!worm
AVGWin32:AutoRun-AOY [Wrm]
PandaW32/Autorun.AJK.worm

How to remove Win32:AutoRun-AOY [Wrm]?

Win32:AutoRun-AOY [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment