Worm

Worm:Win32/Autorun.ABQ (file analysis)

Malware Removal

The Worm:Win32/Autorun.ABQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.ABQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Worm:Win32/Autorun.ABQ?


File Info:

name: 725C84743F1E358F090F.mlw
path: /opt/CAPEv2/storage/binaries/7d7181dc61ccac4d903f7ac4adb7543a1be423310dc3973ed821a52ed1f2deb1
crc32: 64AD3AFD
md5: 725c84743f1e358f090fc6078e122f62
sha1: bd76ce09f07409340593667397ecc250f8a5497b
sha256: 7d7181dc61ccac4d903f7ac4adb7543a1be423310dc3973ed821a52ed1f2deb1
sha512: 7ef1f0ab993e9230f6ca1726dcb23be430fa796939e3e89ba6851c337cc8c37be302f06f9b9514e9303db0c87c7a9c1936a8c81fbb563f7ad19d0d5af7a1fba4
ssdeep: 3072:7a4B5eRp47aJgZeqct7WBB5NcIpomkv2v7MsMun45m0srOZ2G1SYf51YUwcfueB:L524De9UyIpoPvi7cO0srOZ2G1SwueB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111F3D078FB08E1C1C1594131A853E6901FA1BC32B89F49273694FB4F68596D3BB26D3B
sha3_384: fb1220364df4ea2a8d95a64bb29f7cd25e76f23993b1f6e683f7b77c748756174743134c637298dbc8d2cffa027337c3
ep_bytes: 558bec81ec2c050000ff15a41040003d
timestamp: 2010-06-18 04:02:22

Version Info:

0: [No Data]

Worm:Win32/Autorun.ABQ also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner.56069
MicroWorld-eScanGen:Variant.Ser.Midie.988
CAT-QuickHealWorm.Autorun.ABR4
SkyhighBehavesLike.Win32.Generic.ch
McAfeeW32/Autorun.worm.bbu
Cylanceunsafe
VIPREGen:Variant.Ser.Midie.988
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.43f1e3
BitDefenderThetaGen:NN.ZexaF.36802.kqW@auY6Klci
VirITTrojan.Win32.Generic.BSZG
SymantecW32.SillyDC
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.JXC
APEXMalicious
TrendMicro-HouseCallWORM_SWISYN.SMB
ClamAVWin.Trojan.Autorun-9911
KasperskyTrojan.Win32.Swisyn.cpkf
BitDefenderGen:Variant.Ser.Midie.988
NANO-AntivirusTrojan.Win32.Swisyn.cazlv
AvastWin32:GenMalicious-FAM [Trj]
TencentMalware.Win32.Gencirc.10b123c6
EmsisoftGen:Variant.Ser.Midie.988 (B)
F-SecureTrojan.TR/Crypt.EPACK.Gen2
ZillyaTrojan.Swisyn.Win32.13901
TrendMicroWORM_SWISYN.SMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.725c84743f1e358f
SophosW32/Swisyn-AE
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
JiangminTrojan/Swisyn.ndy
GoogleDetected
AviraTR/Crypt.EPACK.Gen2
VaristW32/Caphaw.A.gen!Eldorado
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Autorun.ABQ
XcitiumMalware@#2xzk23wretjh5
ArcabitTrojan.Ser.Midie.988
ViRobotTrojan.Win32.A.Swisyn.164864
ZoneAlarmTrojan.Win32.Swisyn.cpkf
GDataGen:Variant.Ser.Midie.988
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Swisyn.R13544
VBA32BScope.Trojan-Dropper.Injector
ALYacGen:Variant.Ser.Midie.988
TACHYONTrojan-Clicker/W32.Fakealert.167936.J
MalwarebytesMalware.AI.2024349733
PandaGeneric Malware
RisingWorm.Autorun!8.50 (TFE:2:bk93UUbFiPR)
YandexTrojan.GenAsa!rwiYDsQmKkk
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Autorun.BBU!tr
AVGWin32:GenMalicious-FAM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Kryptik.c7306ccd

How to remove Worm:Win32/Autorun.ABQ?

Worm:Win32/Autorun.ABQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment