Worm

Worm:Win32/Autorun.ADN removal guide

Malware Removal

The Worm:Win32/Autorun.ADN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.ADN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Autorun.ADN?


File Info:

name: 9F62070D60B2AC22049A.mlw
path: /opt/CAPEv2/storage/binaries/f44f25da9f05c192cb4bd858cd88cb8ebcd4cd619c9fa27e233a6bc87970c4ee
crc32: 726A5A09
md5: 9f62070d60b2ac22049a68f03880391c
sha1: 690d8cabc28cb400db931e352cc1819389044bdf
sha256: f44f25da9f05c192cb4bd858cd88cb8ebcd4cd619c9fa27e233a6bc87970c4ee
sha512: 1ee3590b58b532a4a891041f4249d01f463639d58707d09b4c5533d15caeaa7802036171f845f3028f4ee16391eae71641d312e75102338bbc44427f01e10aa7
ssdeep: 1536:e5Z99LRh2Uz8LUsKxhECl7lUv6/Znwkgp0bFvFRFjFVFXFnuuNshaQeHwXRp62i:KX9LRhBUCl7lUv6/Z7Vsh0IRC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C793932B778020D7D95446B52CD7B3C319B672851A1B35432E20279AFC66E420B3EAFF
sha3_384: c0a50527bc9601062f37d75154080834fe4ba614262030044c5a2a49a562375f2a61c8c5f3d45d7c6148d61e6c323ecc
ep_bytes: 6840134000e8eeffffff000000000000
timestamp: 2011-02-15 11:30:04

Version Info:

Translation: 0x0409 0x04b0
ProductName: tzKLZZmsoouQrzQKUfU
FileVersion: 1.11
ProductVersion: 1.11
InternalName: RfaIrndLv
OriginalFilename: RfaIrndLv.exe

Worm:Win32/Autorun.ADN also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fm0@sXex0Ukib
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Trojan.Heur.fm0@sXex0Ukib
Cylanceunsafe
VIPREGen:Trojan.Heur.fm0@sXex0Ukib
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0020f7e31 )
BitDefenderGen:Trojan.Heur.fm0@sXex0Ukib
K7GWTrojan ( 0020f7e31 )
Cybereasonmalicious.d60b2a
ArcabitTrojan.Heur.EC376A
BaiduWin32.Worm.AutoRun.cj
VirITTrojan.Win32.Generic.AEOF
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup!gen10
ESET-NOD32a variant of Win32/AutoRun.VB.ABD
APEXMalicious
AvastWin32:VB-REW [Trj]
CynetMalicious (score: 100)
KasperskyWorm.Win32.VBNA.bruy
AlibabaMalware:Win32/km_2f9164.None
NANO-AntivirusTrojan.Win32.VBKrypt.covkrm
SUPERAntiSpywareTrojan.Agent/Gen-VBKrypt
RisingWorm.VobfusEx!1.99EB (CLASSIC)
EmsisoftGen:Trojan.Heur.fm0@sXex0Ukib (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.20458
TrendMicroWORM_VOBFUS.SMIA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nt
Trapminemalicious.moderate.ml.score
SophosW32/SillyFDC-FT
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumPacked.Win32.Krap.BV@2qqlmo
MicrosoftWorm:Win32/Autorun.ADN
ZoneAlarmWorm.Win32.VBNA.bruy
GDataGen:Trojan.Heur.fm0@sXex0Ukib
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R3075
McAfeeVBObfus.f
TACHYONWorm/W32.VBNA.94208
DeepInstinctMALICIOUS
VBA32Trojan.VBRA.010817
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIA
TencentWorm.Win32.Vbna.pm
YandexTrojan.GenAsa!JB/4NGU7+mE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-REW [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Autorun.ADN?

Worm:Win32/Autorun.ADN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment