Worm

Worm:Win32/Autorun.YI malicious file

Malware Removal

The Worm:Win32/Autorun.YI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.YI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Autorun.YI?


File Info:

name: 511F222B5C61B6BD606F.mlw
path: /opt/CAPEv2/storage/binaries/05ad185a7a003c8b8cead14de19548014506ba877988814aaec15cdf3db00aac
crc32: 3F812C7C
md5: 511f222b5c61b6bd606f025cd483a267
sha1: d8f6833ef5c570edf83ce9a42e32824a83f0d3f3
sha256: 05ad185a7a003c8b8cead14de19548014506ba877988814aaec15cdf3db00aac
sha512: 4c1cba6b86989c6d6dd5526880cb8ff7995392778881b56a34f08706dea95ae24166dde44c620dfb32be2365c8769a41d66bc4155c94d9f908cfb4f67bca8d4e
ssdeep: 1536:0nR3Eu9dO/p15Bx8pEttgdO/mXpgWXOJgQmmogDcMH5fCVsJVafuegWXAi+oX9tT:aR3EuXOB15Bx8pEttgdO/mXpgWXOJgQy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1077330B9FAC75806E48405BE175BC1D11263384F2D47A69A13AF3FEF1C04E6A4D29B27
sha3_384: a9ffc8c984fd1aa517f6b1299ab614112fbf7ec5003a72cf62e2a3256aabeef518eaa5bb65898b4b6734acfc639d4531
ep_bytes: 6890124000e8f0ffffff000000000000
timestamp: 2010-02-25 15:39:39

Version Info:

Translation: 0x0409 0x04b0
ProductName: AunhWyqm
FileVersion: 3.72
ProductVersion: 3.72
InternalName: AunhWyqm
OriginalFilename: AunhWyqm.exe

Worm:Win32/Autorun.YI also known as:

BkavW32.FamVT.VBNA.A.Worm
LionicWorm.Win32.VBNA.lJjC
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
ClamAVHtml.Trojan.VBChinky-2
FireEyeGeneric.mg.511f222b5c61b6bd
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.lm
McAfeeVBObfus
Cylanceunsafe
ZillyaWorm.VBNA.Win32.45468
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( f1000d031 )
AlibabaWorm:Win32/Vobfus.3c30a59a
K7GWTrojan ( f1000d031 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Chinky.2
BitDefenderThetaAI:Packer.FFD764AD20
VirITWorm.Win32.VBNA.A
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.MC
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.exjt
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Chinky.hlopyc
AvastWin32:AutoRun-BGR [Wrm]
TencentWorm.Win32.VBna.e
TACHYONWorm/W32.Vobfus.78848
EmsisoftGen:Trojan.Chinky.2 (B)
BaiduWin32.Worm.VBNA.a
F-SecureTrojan.TR/Chinky.G
DrWebWin32.HLLW.VBNA.based
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VBNA.SM
Trapminemalicious.moderate.ml.score
SophosW32/Autorun-BBS
SentinelOneStatic AI – Malicious PE
WebrootW32.Autorun.Gen
GoogleDetected
AviraTR/Chinky.G
Antiy-AVLWorm/Win32.Vobfus
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Chinky.K_20@1p6oe1
MicrosoftWorm:Win32/Autorun.YI
ZoneAlarmWorm.Win32.Vobfus.exjt
GDataGen:Trojan.Chinky.2
VaristW32/Vobfus.D.gen!Eldorado
AhnLab-V3Win32/Vbna3.worm.Gen
Acronissuspicious
VBA32Trojan.VB.01072
ALYacGen:Trojan.Chinky.2
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.CP.worm
TrendMicro-HouseCallWORM_VBNA.SM
RisingTrojan.Autorun!1.DA78 (CLASSIC)
YandexTrojan.GenAsa!DHoP9oN5zVQ
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:AutoRun-BGR [Wrm]
Cybereasonmalicious.ef5c57
DeepInstinctMALICIOUS

How to remove Worm:Win32/Autorun.YI?

Worm:Win32/Autorun.YI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment