Worm

How to remove “Worm.Autorun.2013”?

Malware Removal

The Worm.Autorun.2013 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Autorun.2013 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Worm.Autorun.2013?


File Info:

crc32: 7C3E08C9
md5: 125738d3886ef18260a0227e0c5493e4
name: 125738D3886EF18260A0227E0C5493E4.mlw
sha1: ec5875a22b9111ebf40c348256cb630f076fb71f
sha256: 12cddbe31e047ceab8c4540e87e91b15efc47d6dac6c3e379e027190484d25da
sha512: 66a630bb0da222f9ff72dd3ebb34fdf16fee7a0b864e2914090f0b256239ea0dadb35a6298f9a08af07479409a1a4e0ce315176908cd3c728263e084e4d113c2
ssdeep: 12288:5MMpXKb0hNGh1kG0HWnALBZZmw+VsLkjrVlQB9FbDTF53nlNFRpO50w9XCfyGjNe:5MMpXS0hN0V0HB2wW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm.Autorun.2013 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Stone.1
MicroWorld-eScanTrojan.GenericKD.35672875
FireEyeGeneric.mg.125738d3886ef182
CAT-QuickHealTrojan.Wacatac
McAfeeW32/Autorun.worm.aakg
CylanceUnsafe
SangforWin.Malware.Mepaow-6725393-0
K7AntiVirusP2PWorm ( 004d32291 )
BitDefenderTrojan.GenericKD.35672875
K7GWP2PWorm ( 004d32291 )
Cybereasonmalicious.3886ef
BitDefenderThetaGen:NN.ZelphiF.34590.i5Zbaa85Uzlb
CyrenW32/Spybot.RGMP-5580
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Stihat [Wrm]
ClamAVWin.Malware.Mepaow-6725393-0
KasperskyVirus.Win32.Lamer.cb
NANO-AntivirusVirus.Win32.Mepaow.btvwx
TencentVirus.Win32.Lamer.cb
Ad-AwareTrojan.GenericKD.35672875
TACHYONWorm/W32.DPLamer
SophosML/PE-A + W32/AutoRun-AQR
ComodoVirus.Win32.Stihat.A@8lodcy
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Stihat.Win32.4
TrendMicroTROJ_AGENT_048416.TOMB
McAfee-GW-EditionBehavesLike.Win32.Autorun.tm
EmsisoftTrojan.GenericKD.35672875 (B)
IkarusTrojan.Win32.Mepaow
JiangminPacked.Multi.jhs
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLVirus/Win32.Lamer.cb
MicrosoftTrojan:Win32/Wacatac.D1!ml
GridinsoftTrojan.Win32.Agent.bot!s1
ArcabitTrojan.Generic.D220532B
ZoneAlarmVirus.Win32.Lamer.cb
GDataWin32.Worm.Stihat.B
CynetMalicious (score: 100)
AhnLab-V3Win32/Lamer.F.X2070
Acronissuspicious
VBA32Worm.Autorun.2013
ALYacTrojan.GenericKD.35672875
MAXmalware (ai score=82)
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaGeneric Malware
ESET-NOD32Win32/AutoRun.Stihat.A
TrendMicro-HouseCallTROJ_AGENT_048416.TOMB
RisingTrojan.Injector!1.CC4F (RDMK:cmRtazr/mfLb7yOthjZWr+ruQKIU)
YandexWorm.AutoRun!fl2XQ65mhvo
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Win32.Lamer.CB
FortinetW32/Stone.22A3!tr
AVGWin32:Stihat [Wrm]
Qihoo-360HEUR/QVM13.0.9F3B.Malware.Gen

How to remove Worm.Autorun.2013?

Worm.Autorun.2013 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment