Worm

Worm:Win32/Autorun.UE removal

Malware Removal

The Worm:Win32/Autorun.UE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.UE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Autorun.UE?


File Info:

name: A462B40002250007E462.mlw
path: /opt/CAPEv2/storage/binaries/4ce126b165226a9b0278d8a828b80e90d3b6ed1253d4c146b289d27998028121
crc32: 87DE0561
md5: a462b40002250007e46254c2620014a4
sha1: 36bdccabed70c9984a9430be3e02448864e5f62e
sha256: 4ce126b165226a9b0278d8a828b80e90d3b6ed1253d4c146b289d27998028121
sha512: acee078553c1cc4d053c42a2423fff435b14f6d5d77fd6e951d2dcdb1b756f1486d8ba19fa1b0942e4908f17d9b9f1b5de98c6ad1dd8229fc1bafffaac93bd64
ssdeep: 3072:QRoZBWAJCbL2+LaEdtQqXjuVx3ucPsunjzc5ULc5uszD9dDy6j6:QSZBWAJCbL2+LaEdSVx35P1nnc5ULc5B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBE37F39FA10611DEDE141793C653A3FB6481E7C0A44AA66F7B1464FA0F2BE2B4E4707
sha3_384: fc607e6b1a42a2ff13036a21c23daf6393c4065fffe17d4d7b7db0b045b556e771d8d10f29a0d5305022bb8b351d726d
ep_bytes: 6880244000e8eeffffff000000000000
timestamp: 2009-06-13 14:49:05

Version Info:

0: [No Data]

Worm:Win32/Autorun.UE also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.AutoRun.o!c
DrWebWin32.HLLW.Autoruner.64538
MicroWorld-eScanGen:Variant.Zusy.467601
ClamAVWin.Trojan.VB-1074
FireEyeGeneric.mg.a462b40002250007
CAT-QuickHealWorm.Autorun.UI3
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeW32/Autorun.worm.gk
Cylanceunsafe
ZillyaWorm.AutoRun.Win32.11
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 000cc0491 )
AlibabaWorm:Win32/AutoRun.23315dfe
K7GWP2PWorm ( 000cc0491 )
Cybereasonmalicious.bed70c
BitDefenderThetaAI:Packer.28FA6ECA1E
VirITWorm.Win32.AutoRun.GMS
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.EL
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.AutoRun.gms
BitDefenderGen:Variant.Zusy.467601
NANO-AntivirusTrojan.Win32.AutoRun.wqak
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
AvastWin32:AutoRun-AXV [Wrm]
TencentWorm.Win32.AutoRun.ka
EmsisoftGen:Variant.Zusy.467601 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Autorun.l
VIPREGen:Variant.Zusy.467601
TrendMicroTROJ_GEN.R002C0CLV23
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-D
IkarusTrojan.VB
GDataGen:Variant.Zusy.467601
JiangminWorm/AutoRun.anxg
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.AutoRun
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Autorun.VB_EL0@1isj9n
ArcabitTrojan.Zusy.D72291
ZoneAlarmWorm.Win32.AutoRun.gms
MicrosoftWorm:Win32/Autorun.UE
VaristW32/AutoRun.L.gen!Eldorado
AhnLab-V3Worm/Win.AutoRun.R485143
Acronissuspicious
VBA32OScope.Trojan.VB.01580
ALYacGen:Variant.Zusy.467601
MAXmalware (ai score=88)
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Autorun.JQN
TrendMicro-HouseCallTROJ_GEN.R002C0CLV23
RisingTrojan.Win32.VBCode.akg (CLASSIC)
YandexTrojan.GenAsa!vgzaXTv/ojM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.29150.susgen
FortinetW32/VBNA.B!tr
AVGWin32:AutoRun-AXV [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Autorun.UE?

Worm:Win32/Autorun.UE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment