Worm

Worm:Win32/Autorun.GX removal tips

Malware Removal

The Worm:Win32/Autorun.GX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.GX virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Worm:Win32/Autorun.GX?


File Info:

name: 74114C251C6FA7815363.mlw
path: /opt/CAPEv2/storage/binaries/c5a5ad82213ceea8f98f3384edcd555b1cab61569126873e02b00611bd764b9f
crc32: 2EA4CAC7
md5: 74114c251c6fa781536363d67a29e089
sha1: 600490793829a9a9c4a10b1d6a77c2cbedd1fc5d
sha256: c5a5ad82213ceea8f98f3384edcd555b1cab61569126873e02b00611bd764b9f
sha512: fbf940ca029954f298e09347b35878967bbbe785c6b07fe7facb0b262c9dc5eb3ca7faae2f3088637a137cb34a5d14752b8e6f94ab9cd9afc99e7607a4cd6866
ssdeep: 1536:QSpe+sd5jcfNfp8naKmNcQNqIJNaqFYOS6ySE7KagPL0OXMTmK6C1chPs1A2LPEd:hSAfv13zIxdLPIVolMxeuIXiv2/JKP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3B33BC431A62E64F6DB8FB4A285DB6CF5F72C136752C590A80452BA0E5EEC93F17C18
sha3_384: ac2e7868c51e405f7ec71b4f41adda0cfd78e1af267a583616c87f7c48b5a16d6f7ab2a6c8c4f6213b88f69c84ca5538
ep_bytes: 52565183c9055053570f85fefeffff60
timestamp: 1972-12-25 05:33:23

Version Info:

0: [No Data]

Worm:Win32/Autorun.GX also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.EvilEPL.6
FireEyeGeneric.mg.74114c251c6fa781
CAT-QuickHealTrojan.FlyStudio.UJ
SkyhighBehavesLike.Win32.Generic.ch
McAfeeFlyagent.b
MalwarebytesMalware.Heuristic.2090
K7AntiVirusEmailWorm ( 0009aeed1 )
AlibabaWorm:Win32/FlyStudio.84c57403
K7GWEmailWorm ( 0009aeed1 )
Cybereasonmalicious.51c6fa
BitDefenderThetaAI:Packer.5FC2631C1C
SymantecBackdoor.Trojan
ESET-NOD32Win32/AutoRun.FlyStudio.IH
APEXMalicious
TrendMicro-HouseCallWORM_AUTORUN.BDH
AvastWin32:ScramEPL [Cryp]
ClamAVWin.Worm.FlyStudio-33
KasperskyWorm.Win32.FlyStudio.cd
BitDefenderGen:Variant.EvilEPL.6
NANO-AntivirusVirus.Win32.Agent.dvixmz
TencentTrojan.Win32.Autorun.uu
EmsisoftGen:Variant.EvilEPL.6 (B)
BaiduWin32.Trojan.FlyStudio.ob
F-SecureTrojan-Dropper:W32/Peed.gen!A
DrWebWin32.HLLW.Autoruner.6411
VIPREGen:Variant.EvilEPL.6
TrendMicroWORM_AUTORUN.BDH
Trapminemalicious.high.ml.score
SophosMal/EncPk-NB
IkarusTrojan.Gendal
MAXmalware (ai score=100)
JiangminBackdoor/FlyAgent.hp
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
VaristW32/Backdoor2.DSAQ
Antiy-AVLVirus/Win32.Expiro.rsrc
KingsoftWin32.Troj.FuckCryptT.d.114176
MicrosoftWorm:Win32/Autorun.GX
XcitiumWorm.Win32.Autorun.ABC@1r4z6o
ArcabitTrojan.EvilEPL.6
ViRobotWorm.Win32.A.FlyStudio.114176.NT
ZoneAlarmWorm.Win32.FlyStudio.cd
GDataGen:Variant.EvilEPL.6
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FlyStudio.R2520
ALYacGen:Variant.EvilEPL.6
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
RisingWorm.Win32.Autorun.fje (CLASSIC)
YandexWorm.FlyStudio.AXW.Gen
SentinelOneStatic AI – Malicious PE
MaxSecureNot-a-Virus.FlyStdio.L
FortinetW32/PckdFlyStudio.gen
AVGWin32:ScramEPL [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/FlyStudio.IH

How to remove Worm:Win32/Autorun.GX?

Worm:Win32/Autorun.GX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment