Malware

Win32:AutoRun-CNI [Trj] removal

Malware Removal

The Win32:AutoRun-CNI [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:AutoRun-CNI [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:AutoRun-CNI [Trj]?


File Info:

name: 71AF457EACDF8F67B576.mlw
path: /opt/CAPEv2/storage/binaries/842adcce64598f0ef6233c00615de735218a159cda5020216f71448f3c06d087
crc32: 2384111C
md5: 71af457eacdf8f67b5760190c85b631d
sha1: db4b97b91209d7ebc92bb07113ade6df3b782bc0
sha256: 842adcce64598f0ef6233c00615de735218a159cda5020216f71448f3c06d087
sha512: 95e6168ff68b977ed011830c8e30b9c3c3e1cf0b65510f2cf3abe4ce227e4b08c6fa8bfe0edbc2b09b7a08a64f67ea0bd6db128cc3ea28058da2df0968d3aab8
ssdeep: 6144:SftTPlptNvl9fm0UBFsqMabeYiUDogAFJ:SR9n9lJvaFsqMv3J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E544A21572C0F63AD561C6F43A5643A8953EEC3324A1A847F7D21F2A37B1E87E221763
sha3_384: d214c65094da7514f270d3dfef9865dcb0d96f9cd90262ee4babb8f920d60e1cafbd2de33985c29043070972aaf57f03
ep_bytes: 68883f4000e8f0ffffff000000000000
timestamp: 2012-01-13 17:13:11

Version Info:

0: [No Data]

Win32:AutoRun-CNI [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Sirefef.942
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.eacdf8
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.Zyx.HO
SymantecW32.Changeup!gen15
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AQN
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.efkb
BitDefenderGen:Variant.Sirefef.942
NANO-AntivirusTrojan.Win32.Diple.cihuge
SUPERAntiSpywareTrojan.Agent/Gen-Multi[VB]
AvastWin32:AutoRun-CNI [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Sirefef.942 (B)
F-SecureTrojan.TR/Diple.ejbmna
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Sirefef.942
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.71af457eacdf8f67
SophosW32/VB-FSP
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
GoogleDetected
AviraTR/Diple.ejbmna
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.Diple.EMIB@4pez3w
ArcabitTrojan.Sirefef.942
ViRobotTrojan.Win32.A.Diple.262144.D
ZoneAlarmWorm.Win32.Vobfus.efkb
GDataGen:Variant.Sirefef.942
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R19780
Acronissuspicious
VBA32BScope.Worm.Vobfus
ALYacGen:Variant.Sirefef.942
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!SaCOTwa1z30
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Diple.ejsq
FortinetW32/Diple.EJQE!tr
BitDefenderThetaGen:NN.ZevbaF.36802.qmW@a4krxAni
AVGWin32:AutoRun-CNI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Vobfus.fb85dd37

How to remove Win32:AutoRun-CNI [Trj]?

Win32:AutoRun-CNI [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment