Malware

Win32:AutoRun-CMJ [Trj] removal guide

Malware Removal

The Win32:AutoRun-CMJ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:AutoRun-CMJ [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:AutoRun-CMJ [Trj]?


File Info:

name: CC1CE1CB0090D2042E38.mlw
path: /opt/CAPEv2/storage/binaries/850253e3444a234d01ba25e9d54969f524392cab83374e9af4be1712cc234bc4
crc32: D137E69B
md5: cc1ce1cb0090d2042e38676149e865db
sha1: 633bb0a3d92fce8403bc2aa464d9b8f7ee0881ca
sha256: 850253e3444a234d01ba25e9d54969f524392cab83374e9af4be1712cc234bc4
sha512: bc5b23c51843176a443f18011e60b0d0309f80517e5e9dd12cfac82e005f242036cbbe65bca879ac7e9f78273ef9c407063f77cdde86d4d154feab4326163e83
ssdeep: 6144:nhijKAN+tytpx96Hg02BCh3FZuhbYaxUG2nIVeUut3:nhiefyDxsHg02BCh3FZuhbYaxUG2npUM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10954E7297290FB3AE065C1F13A5A83A4553EED7624B4A807F7D22F2A73B0D57D061723
sha3_384: 08021183e9c1daf9b9229988212ac2e0e6e52cc09c784a57d73b9da9371452a245364f9e2268f723cae19e8f2cac1833
ep_bytes: 68ac434000e8f0ffffff000040000000
timestamp: 2012-01-04 19:14:12

Version Info:

0: [No Data]

Win32:AutoRun-CMJ [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.4173
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Ser.Zusy.4173
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.b0090d
ArcabitTrojan.Ser.Zusy.D104D
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Zyx.HC
SymantecW32.Changeup!gen15
ESET-NOD32Win32/AutoRun.VB.AQE
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_006413.TOMB
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.dfhy
BitDefenderGen:Variant.Ser.Zusy.4173
NANO-AntivirusTrojan.Win32.VB.chvyxv
AvastWin32:AutoRun-CMJ [Trj]
TencentMalware.Win32.Gencirc.10be9c3e
SophosTroj/VB-FSK
F-SecureTrojan.TR/Jorik.Vobfus.klo
DrWebTrojan.VbCrypt.150
TrendMicroTROJ_AGENT_006413.TOMB
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.cc1ce1cb0090d204
EmsisoftGen:Variant.Ser.Zusy.4173 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
GoogleDetected
AviraTR/Jorik.Vobfus.klo
VaristW32/Vobfus.AI.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Vobfus.MJ@8ekc4q
MicrosoftWorm:Win32/Vobfus.gen!P
ViRobotWorm.Win32.A.WBNA.294912.S
ZoneAlarmWorm.Win32.Vobfus.dfhy
GDataGen:Variant.Ser.Zusy.4173
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R36357
Acronissuspicious
VBA32BScope.Trojan.Diple
ALYacGen:Variant.Ser.Zusy.4173
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Pronoy!1.9A2F (CLASSIC)
YandexTrojan.GenAsa!Dw5VOrzCHWM
IkarusSality.Win32
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaAI:Packer.2C00F6471E
AVGWin32:AutoRun-CMJ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Fake.CZ

How to remove Win32:AutoRun-CMJ [Trj]?

Win32:AutoRun-CMJ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment