Worm

Worm.AutoRun.Generic removal guide

Malware Removal

The Worm.AutoRun.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.AutoRun.Generic virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable or modify Explorer Folder Options

How to determine Worm.AutoRun.Generic?


File Info:

name: FAC8FBD711CC1D629288.mlw
path: /opt/CAPEv2/storage/binaries/8b494b3eb7a304a48c955399720f7253df087afb1e78f49e1b5711d918ce6a87
crc32: D1D51195
md5: fac8fbd711cc1d62928820889aa05f37
sha1: 86ffcb805f096437f8c37771a2f933e11ead0452
sha256: 8b494b3eb7a304a48c955399720f7253df087afb1e78f49e1b5711d918ce6a87
sha512: 27f506dccc3c58e2757d879c336a4152429786add8be00b9d29b3956f9d7afa595cf201b88be917de7e8a4adeae8df26891cf62863cb264d8ea04972f075d796
ssdeep: 6144:wpqoa8aLiC/2OLSAN7gNVpNleQUohBfGPOtQciXeL/XYqGlebojSP2pjNhcRYnCS:wpqiC/2OGAtkCP4cejGSOpRKGC8RP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169D48D02B7C680F5D8A339711577E32AEB3979154326C69BEFE02E628E115709F3A371
sha3_384: 38055edde5bced96e6c9fcd3e361eed35a40f3aa86297eb7cdd86d879c0ceedc34541e089056592392c2a5fa6c7c62ed
ep_bytes: 53565755fc648b15300000008b520c8b
timestamp: 2008-12-24 09:00:07

Version Info:

0: [No Data]

Worm.AutoRun.Generic also known as:

BkavW32.AlterEIP.PE
Elasticmalicious (high confidence)
DrWebTrojan.Starter.1215
MicroWorld-eScanTrojan.Generic.3272683
FireEyeGeneric.mg.fac8fbd711cc1d62
CAT-QuickHealTrojan.Patched.AM
ALYacTrojan.Generic.3272683
CylanceUnsafe
ZillyaVirus.Starter.Win32.1
K7AntiVirusTrojan ( 00133ee01 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 00133ee01 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.44866B6B18
CyrenW32/Trojan.MMQY-0462
SymantecTrojan.Zbot!inf
ESET-NOD32Win32/TrojanDownloader.Small.OUC
TrendMicro-HouseCallPE_ZBOT.A
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-1267
KasperskyTrojan.Win32.ZbotPatched.b
BitDefenderTrojan.Generic.3272683
ViRobotWin32.PatchedZBot.A
RisingTrojan.DL.Win32.Rugo.c (CLASSIC)
Ad-AwareTrojan.Generic.3272683
SophosML/PE-A + Troj/Zbot-NY
ComodoTrojWare.Win32.Patched.O@1mj32s
BaiduAutoIt.Worm.Autorun.a
VIPREVirus.Win32.Zbot.a (v)
EmsisoftTrojan.Generic.3272683 (B)
IkarusWorm.Win32.AutoIt
JiangminTrojanDownloader.Genome.ghl
MaxSecureVirus.W32.ZbotPatched.A
AviraWORM/Autorun.esf
Antiy-AVLTrojan/Generic.ASCommon.11C
KingsoftWin32.Troj.Generic.a.(kcloud)
CynetMalicious (score: 100)
AhnLab-V3HEUR/Fakon.mwf.X1381
MalwarebytesWorm.AutoRun.Generic
APEXMalicious
TencentWin32.Trojan.Zbotpatched.Egoe
YandexWin32.ZBot.RSI
MAXmalware (ai score=100)
eGambitUnsafe.AI_Score_56%
FortinetW32/Genome.ABYW!tr.dldr
Cybereasonmalicious.711cc1
PandaW32/Patched.L

How to remove Worm.AutoRun.Generic?

Worm.AutoRun.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment