Worm

Worm:Win32/Autorun.ACM removal

Malware Removal

The Worm:Win32/Autorun.ACM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.ACM virus can do?

  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Worm:Win32/Autorun.ACM?


File Info:

name: 6FE735A61AA713A866C5.mlw
path: /opt/CAPEv2/storage/binaries/a5f350ee14ce2edde7a3a6a1bfbc5fcde0aa50259ef3e5ee11d0677e7abfa5f7
crc32: FCA2E09B
md5: 6fe735a61aa713a866c50f64c3a5e2a2
sha1: dfb099a1d0954bbb65b866339d11c894f4cc6a97
sha256: a5f350ee14ce2edde7a3a6a1bfbc5fcde0aa50259ef3e5ee11d0677e7abfa5f7
sha512: 5e2ba7eadece6e63e4657a59aa75175346e0fef7f14a21dac2e3d4dad36dbd566773d7a5d553e0d7bfc5f20f745f3c471a2e42bf73409fffb4b07c4e6abe9e27
ssdeep: 12288:kkmtWbZcw+VxGMm4mKhmHn6DbTnTH4W26f9BowofkGj7:1VSxqNEJ26f9ofkG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BB4E2D202E49EECFFDC8DFD4819340E76283D1DDAB0E5459DC1306475ADBA92D02AAE
sha3_384: 4747ae2d8e23cb0732e95e2186d36bfc1bd4268f5d51daf9a1da1a6808b899ecbdf8ec9d38117898ba5aaa14bc676d37
ep_bytes: ff250020400000000000000000000000
timestamp: 2011-05-01 11:45:53

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: koko12.exe
LegalCopyright:
OriginalFilename: koko12.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Worm:Win32/Autorun.ACM also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.llAB
Elasticmalicious (high confidence)
DrWebBackDoor.Cybergate.1
MicroWorld-eScanTrojan.MSIL.Basic.3.Gen
FireEyeGeneric.mg.6fe735a61aa713a8
SkyhighBehavesLike.Win32.Generic.hh
McAfeeGenericRXAC-RF!6FE735A61AA7
MalwarebytesMalware.AI.22306800
SangforSuspicious.Win32.Save.a
AlibabaWorm:Win32/Autorun.05f5131d
Cybereasonmalicious.61aa71
BitDefenderThetaGen:NN.ZemsilF.36802.Fm0@aWfWQSj
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Small.Y
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.MSIL.Basic.3.Gen
NANO-AntivirusTrojan.Win32.Cybergate.dbidmd
AvastMSIL:Inject-AE [Trj]
TencentWin32.Trojan.Generic.Hflw
EmsisoftTrojan.MSIL.Basic.3.Gen (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Injector.Win32.18984
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusGen.Variant.MSILKrypt
GDataTrojan.MSIL.Basic.3.Gen
JiangminTrojan/Generic.dzys
VaristW32/Trojan.DIA.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
XcitiumMalware@#252h96nty2xi9
ArcabitTrojan.MSIL.Basic.3.Gen
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Autorun.ACM
ALYacTrojan.MSIL.Basic.3.Gen
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
RisingWorm.Autorun!8.50 (CLOUD)
YandexTrojan.PWS.Fignotok!1PXmz6YmnWM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetMSIL/Injector.DK
AVGMSIL:Inject-AE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan

How to remove Worm:Win32/Autorun.ACM?

Worm:Win32/Autorun.ACM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment