Malware

Win32:AutoRun-CPC [Trj] (file analysis)

Malware Removal

The Win32:AutoRun-CPC [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:AutoRun-CPC [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:AutoRun-CPC [Trj]?


File Info:

name: 949A04B19CE1370EFCE5.mlw
path: /opt/CAPEv2/storage/binaries/02756a5f9eb34ad1fc3f3bbd56ba778c29a87767b750a94b9629737ff37ce7eb
crc32: 2264E2ED
md5: 949a04b19ce1370efce5d0d7f715824d
sha1: a76fcfcbf5b9a7a45ffaad509db0268a824a3f1f
sha256: 02756a5f9eb34ad1fc3f3bbd56ba778c29a87767b750a94b9629737ff37ce7eb
sha512: 02017163c405355e90511c61fff633d902a6383c5f1c95fa6f5af0a54f4344c8a32965f48cc785e7bc882609ae8e1560805ca93cf7cdc3c226a4411cccd7cdd8
ssdeep: 6144:H2aIfrt3+TetonBi3QxRy4g09ICSnqf9uSUgkxtpsaPjK/bEoK828fwAoEn+MH:H2Vrt3+TetonBi3QxRwfnqf9uSUgkxtW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E124F7BAB260A33EE916C5F53D6986D8042E6D361496E803F7C56F19B6F1E83D132313
sha3_384: 0d293951868dcb58f5af18e23e542fbc5aa67226b0e5d3c2e2b834b615be5b1d1ca1bfa17a52f57c73ada7c0bc0766be
ep_bytes: 68c03d4000e8f0ffffff000040000000
timestamp: 2012-01-26 18:11:27

Version Info:

Translation: 0x0409 0x04b0
ProductName: eHVqCN
FileVersion: 1.00
ProductVersion: 1.00
InternalName: UVcsHuBSJw
OriginalFilename: UVcsHuBSJw.exe

Win32:AutoRun-CPC [Trj] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lrSX
MicroWorld-eScanGen:Variant.Chinky.7
FireEyeGeneric.mg.949a04b19ce1370e
CAT-QuickHealTrojan.VBCryptVMF.S29376679
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.cm
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Vobfus.Win32.1519971
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff7.None
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.VBKrypt.IZAA
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.ARA
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
Paloaltogeneric.ml
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dfdw
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.VBKrypt.cqkxzs
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
AvastWin32:AutoRun-CPC [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Chinky.7 (B)
F-SecureTrojan.TR/VBKrypt.izaas
DrWebWin32.HLLW.Autoruner2.15099
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-HE
IkarusWorm.Win32.Vobfus
MAXmalware (ai score=89)
JiangminTrojan.VBKrypt.avgd
GoogleDetected
AviraTR/VBKrypt.izaas
VaristW32/Vobfus.AI.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!P
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Chinky.7
ViRobotTrojan.Win32.A.VBKrypt.221184.CU
ZoneAlarmWorm.Win32.Vobfus.dfdw
GDataGen:Variant.Chinky.7
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R19758
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.nm0@am8TJ@mi
ALYacGen:Variant.Chinky.7
TACHYONWorm/W32.Vobfus.221184.C
VBA32BScope.Trojan.VBCR.2512
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!fyoF4D3jTo0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:AutoRun-CPC [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.d9b1a315

How to remove Win32:AutoRun-CPC [Trj]?

Win32:AutoRun-CPC [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment