Worm

Should I remove “Worm.Autorun.ne”?

Malware Removal

The Worm.Autorun.ne is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Autorun.ne virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm.Autorun.ne?


File Info:

name: 41184954F89DC41314CE.mlw
path: /opt/CAPEv2/storage/binaries/41a170ff9c03e284c4c972113d3ff4a83348e8fe3c0db49c6936fa8e618db8a9
crc32: 1B62B76C
md5: 41184954f89dc41314ce6f11294a55f9
sha1: 8da3bddae09557e3f0c5288ac82d64ca858a94a5
sha256: 41a170ff9c03e284c4c972113d3ff4a83348e8fe3c0db49c6936fa8e618db8a9
sha512: f637c2e529915ac48a3794f86db5c3e1e2a989f9e197908a3076859da33b83803b62f15bb54648129b928b4e87ba6b88250494f8d9af1cb022529a40f762963e
ssdeep: 768:KnbEUh3fy8YyqV1mtThZAXAWhNefwMJ7BikibDVgPsNE+TC84VBIxDfiQoP9aK/k:8bv3ahJkhZyh6w6ikEPTd4Vq3UT8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159E3B262F3C18F1BE95917B58BED868C36B1E18A4B4B5B0F3099D75DBE013F9684E180
sha3_384: e16a552c5bc54a5e48abe24814b6430977824c26b22f766b9541da4455c0a06b440e4477c313f41cc3020ed7c0393c8f
ep_bytes: 60681e8d0200680010400068e3a44700
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.Autorun.ne also known as:

BkavW32.AIDetect.malware1
DrWebWin32.HLLP.Stone.3
MicroWorld-eScanTrojan.GenericKDZ.87278
McAfeeGenericRXDT-PB!41184954F89D
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.ae0955
CyrenW32/Bero.A.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
TrendMicro-HouseCallMal_Bero
ClamAVWin.Malware.Mepaow-6725393-0
BitDefenderTrojan.GenericKDZ.87278
Ad-AwareTrojan.GenericKDZ.87278
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Patched.KSU@5t5qg6
TrendMicroMal_Bero
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.41184954f89dc413
EmsisoftTrojan.GenericKDZ.87278 (B)
IkarusWin32.Heur
GDataTrojan.GenericKDZ.87278
JiangminTrojan.Generic.hgvpl
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Bero.R481025
VBA32Worm.Autorun.ne
ALYacTrojan.GenericKDZ.87278
APEXMalicious
MAXmalware (ai score=84)
FortinetW32/Bero.70D1!tr
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Worm.Autorun.ne?

Worm.Autorun.ne removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment