Worm

Worm:Win32/Autorun.KA!MTB removal

Malware Removal

The Worm:Win32/Autorun.KA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.KA!MTB virus can do?

  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Polish
  • Authenticode signature is invalid

How to determine Worm:Win32/Autorun.KA!MTB?


File Info:

name: A0D541134B478AC6E09D.mlw
path: /opt/CAPEv2/storage/binaries/a29bfd3b7ae875187e375108f8f40b55a29b2c317bca8c1c6c120ec32ad7a659
crc32: 64CA6E41
md5: a0d541134b478ac6e09d06eacc3d751c
sha1: d9b5e835f079a55221fcb15756b78130efa06c8d
sha256: a29bfd3b7ae875187e375108f8f40b55a29b2c317bca8c1c6c120ec32ad7a659
sha512: 9f71eeca5e687ab1cfb7d0888001c07f9903899dfa1fcf44279d826a7d224de0033ca4b8be66b2a1327547806056021bc5f1fda22e3db31125380956387556ae
ssdeep: 98304:K2JjN5P2JjN5lMMHMMMvMMZMMMlmMMMiMMMYJMMHMMM6MMZMMMqNMMzMMMUMMVML:K21P21x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164767C22F681C837D06216709D6B96B5A436FE242E24897B37E47F0C5F753812E362B7
sha3_384: 4bdd3b5911204f840dd15de1c4a0cf241b0f3591eb8f55070b3782321e1422a7ef00cfc45734a5a213a2b2a2ddea5b55
ep_bytes: eb1066623a432b2b484f4f4b90e99810
timestamp: 2008-05-16 14:05:40

Version Info:

0: [No Data]

Worm:Win32/Autorun.KA!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.6889537
FireEyeGeneric.mg.a0d541134b478ac6
ALYacTrojan.Generic.6889537
CylanceUnsafe
ZillyaTrojan.Agent.Win32.8076
SangforTrojan.Win32.Save.a
K7AntiVirusP2PWorm ( 00058c501 )
K7GWP2PWorm ( 00058c501 )
Cybereasonmalicious.34b478
CyrenW32/Trojan.FCFP-6332
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.NAQ
TrendMicro-HouseCallTROJ_AGENT_000006c.TOMA
ClamAVWin.Trojan.Agent-122208
KasperskyTrojan.Win32.Agent.avjn
BitDefenderTrojan.Generic.6889537
NANO-AntivirusTrojan.Win32.Autoruner.giwhpr
AvastWin32:Small-MOF [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.Generic.6889537
EmsisoftTrojan.Generic.6889537 (B)
ComodoVirus.Win32.AutoRun.NAQ0@1lq7lu
DrWebWin32.HLLW.Autoruner.6848
TrendMicroTROJ_AGENT_000006c.TOMA
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
SophosML/PE-A + W32/Autorun-CFO
APEXMalicious
GDataTrojan.Generic.6889537
JiangminTrojan.Generic.hdtnq
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1107668
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.445CB
ViRobotTrojan.Win32.Agent.1028608
MicrosoftWorm:Win32/Autorun.KA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Agent.R300654
McAfeeGeneric.bmp
VBA32Trojan.Agent
MalwarebytesMalware.AI.730690996
IkarusVirus.Win32.AutoRun
YandexTrojan.GenAsa!bmP+U+9tg0o
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/AutoRun.NAQ!tr
AVGWin32:Small-MOF [Trj]
PandaTrj/Genetic.gen

How to remove Worm:Win32/Autorun.KA!MTB?

Worm:Win32/Autorun.KA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment