Worm

About “Worm:Win32/Autorun.NX” infection

Malware Removal

The Worm:Win32/Autorun.NX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.NX virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm:Win32/Autorun.NX?


File Info:

name: 87C6C050024D31829262.mlw
path: /opt/CAPEv2/storage/binaries/e20f23b71e4d164994f8ec0da80d4312665e3352f7dc49106372668f6875bc73
crc32: B8FE528B
md5: 87c6c050024d318292623fab3a96a47f
sha1: f090576d1eab84cb53e31b9b84e95b05786e72c6
sha256: e20f23b71e4d164994f8ec0da80d4312665e3352f7dc49106372668f6875bc73
sha512: 2270fb5d46654b15edd764d7c648c0d0672dce25fc40dda70fcdae0ed7e8da6205d5b64a9abf8c9bcf4956d56fdc1cfc6def5a1c627d8088432e1253915bfda5
ssdeep: 24576:gvrYzcr1oNLmdeeqxoD46mJvC0QErsh2lrYitcr1R2ydMQiLhbeeE7npoD46mJvN:JSs+EghAN+nsE3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A159E26F39184B2D037197D8C1B63B8999D7EA12D19AC463AE83D4D1F393D03D2A397
sha3_384: de9012064f2c96014179912edb15f4c5193694ec4464c58b69f5cffefbbedbc54e3fe29555161760db01fd11a0602a36
ep_bytes: 558bec83c4f0b8c4f74400e89c63fbff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Worm:Win32/Autorun.NX also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-BRL [Wrm]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.301702
FireEyeGeneric.mg.87c6c050024d3182
CAT-QuickHealWorm.Autorun.9771
SkyhighBehavesLike.Win32.ObfuscatedPoly.ch
McAfeeW32/Autorun.worm.u
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.d1eab8
BitDefenderThetaGen:NN.ZelphiF.36744.4GZ@aSovwLhb
VirITWorm.Win32.Autorun.GAR
SymantecTrojan Horse
ESET-NOD32Win32/Delf.NQA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Ulise-9808222-0
KasperskyWorm.Win32.Autorun.gar
BitDefenderGen:Variant.Zusy.301702
NANO-AntivirusTrojan.Win32.Hesv.fkepvj
AvastWin32:AutoRun-BRL [Wrm]
TencentWorm.Win32.AutoRun.id
EmsisoftGen:Variant.Zusy.301702 (B)
BaiduWin32.Worm.Delf.f
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner1.14752
VIPREGen:Variant.Zusy.301702
TrendMicroWORM_OTORUN.SMO
Trapminemalicious.high.ml.score
SophosMal/Autorun-AQ
IkarusHoax.Win32.IMPass
JiangminWorm/AutoRun.hwk
WebrootW32.Worm.Autorun
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.Autorun
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Autorun.NX
XcitiumTrojWare.Win32.Trojan.Agent.~IPX@7062v
ArcabitTrojan.Zusy.D49A86
ZoneAlarmWorm.Win32.Autorun.gar
GDataGen:Variant.Zusy.301702
VaristW32/FakeFolder.I.gen!Eldorado
AhnLab-V3Trojan/Win32.Blackhole.R91370
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.301702
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/FakeFolder.H
TrendMicro-HouseCallWORM_OTORUN.SMO
RisingWorm.IncaseFormat!1.D153 (CLASSIC)
YandexTrojan.GenAsa!ZovamWSS8Zg
SentinelOneStatic AI – Malicious PE
FortinetW32/AutoRun.GAR!worm
ZonerTrojan.Win32.68836
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Autorun.NX?

Worm:Win32/Autorun.NX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment