Worm

Worm:Win32/Autorun.NC (file analysis)

Malware Removal

The Worm:Win32/Autorun.NC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.NC virus can do?

  • Authenticode signature is invalid

How to determine Worm:Win32/Autorun.NC?


File Info:

name: A15DA88657B423C4E88D.mlw
path: /opt/CAPEv2/storage/binaries/f3a396da3c9fabd0f2e1c73de6c8b9a36554f1cb29ce8226c6397e36b5a8469a
crc32: D20EAE9E
md5: a15da88657b423c4e88defbe7727fbbd
sha1: 2439ca5b7e870f47c1c28296720d96e1132d5215
sha256: f3a396da3c9fabd0f2e1c73de6c8b9a36554f1cb29ce8226c6397e36b5a8469a
sha512: 2776aa30ba3e2761b173a7bc3d61d57145d0d28028954abe321e73ac94af31c46c91f76778d917c96c310df37b2de02c3c7020176c7c4411e150e4c0191b17af
ssdeep: 768:XcZ+QyvhDvgOpU/WGGIegFDhNmvdMYXqYt1NEDIefZsD:Xk8vgO2/rEgzNLoZt1y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182632F73B6B35C4AD5C67EBA2B839DEA0573A04D0F533661F290872DB628E6014D7E43
sha3_384: 8d76273a1b1ca4d82dc249efee763d5ec883de405c808be18ff72929bf3e119176dbca33c7ed6319213763fb75d11847
ep_bytes: 6808124000e8f0ffffff000000000000
timestamp: 2009-06-15 16:18:44

Version Info:

Translation: 0x0409 0x04b0

Worm:Win32/Autorun.NC also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Chinky.2
ClamAVWin.Trojan.VB-1045
FireEyeGeneric.mg.a15da88657b423c4
CAT-QuickHealWorm.Autorun.NC3
SkyhighBehavesLike.Win32.VBObfus.km
McAfeeW32/VBNA.worm.gen.c
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Chinky.2
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( f1000d031 )
K7GWTrojan ( f1000d031 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.7435B9D21F
VirITTrojan.Win32.Small.TV
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.EW
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.ewvl
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Autoruner.covloz
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
AvastWin32:AutoRun-AYY [Wrm]
TencentWorm.Win32.Vb.wc
TACHYONWorm/W32.Vobfus.69120
EmsisoftGen:Trojan.Chinky.2 (B)
BaiduWin32.Worm.AutoRun.aw
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.7155
TrendMicroWORM_AUTORUN.FHE
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-DS
IkarusTrojan.VB.Inject
GDataGen:Trojan.Chinky.2
VaristW32/VB.W.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VB
XcitiumTrojWare.Win32.TrojanDropper.Multi.TD4@1ej36z
ArcabitTrojan.Chinky.2
ZoneAlarmWorm.Win32.Vobfus.ewvl
MicrosoftWorm:Win32/Autorun.NC
GoogleDetected
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
ALYacGen:Trojan.Chinky.2
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaAdware/AccesMembre
TrendMicro-HouseCallWORM_AUTORUN.FHE
RisingWorm.Win32.VB.xi (CLASSIC)
YandexTrojan.GenAsa!0qTotRoDViQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/VBNA.G!tr
AVGWin32:AutoRun-AYY [Wrm]
Cybereasonmalicious.b7e870
DeepInstinctMALICIOUS

How to remove Worm:Win32/Autorun.NC?

Worm:Win32/Autorun.NC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment