Worm

Worm:Win32/Autorun.ZG removal

Malware Removal

The Worm:Win32/Autorun.ZG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.ZG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Autorun.ZG?


File Info:

name: 099231705D0E9DB29B4B.mlw
path: /opt/CAPEv2/storage/binaries/20f287a5d5d9f9c9ca623a88e9a81af23008207bdaa82220923ae6b9910ae622
crc32: 792E3950
md5: 099231705d0e9db29b4b15f669f7eb65
sha1: d1a4906fc83e5efba55e98276e35f995c345fa4f
sha256: 20f287a5d5d9f9c9ca623a88e9a81af23008207bdaa82220923ae6b9910ae622
sha512: 31648d473acf19e74ae594e85a2ebe023b773c2d27c8a1e4153b6545c1559d5bbed1385fa061385721b9ad16c1625794f09235a5dd8d4a1319538a9144e47ec4
ssdeep: 12288:AgrsmKK14EjEdmZ774kdXiu4UMuoezigu5caE8Gq92e329CC2TyxHSAnMPOHM8u9:uAJZoeiRdEPMWBMyxyAM23vB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A2512336B60DA27C72C423895A285184CEDEE83CE15DE1B3E8979DF25F336245676C2
sha3_384: 1f88536ff5307d643a7c25029410a3011482b88dac9fc214f3ffa08b5e95ab5173e3fdfae544f4c3352164d23a8bc9a1
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-06-09 10:57:38

Version Info:

Translation: 0x0000 0x04b0
Comments: Windows Win32 Application Launcher
CompanyName: Microsoft
FileDescription:
FileVersion: 2.3.0.0
InternalName: poly.exe
LegalCopyright: Copyright © Microsoft Corp. 1981-2010
LegalTrademarks: Copyright © Microsoft Corp. 1981-2010
OriginalFilename: poly.exe
ProductName: Microsoft
ProductVersion: 2.3.0.0
Assembly Version: 3.10.0.0

Worm:Win32/Autorun.ZG also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.MSILPerseus.179529
ClamAVWin.Trojan.KillAV-49
McAfeeGenericRXOR-HP!099231705D0E
Cylanceunsafe
VIPREGen:Variant.MSILPerseus.179529
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004c4c501 )
AlibabaWorm:Win32/Autorun.6ad9cf14
K7GWTrojan ( 004c4c501 )
Cybereasonmalicious.05d0e9
CyrenW32/MSIL_Troj.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Autorun.Agent.IJ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.MSILPerseus.179529
NANO-AntivirusTrojan.Win32.Drop.dkkxet
SUPERAntiSpywareTrojan.Agent/Gen-MSFake[Ply]
AvastMSIL:AutoRun-AF [Trj]
TencentMalware.Win32.Gencirc.115c6b49
EmsisoftGen:Variant.MSILPerseus.179529 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen3.28818
ZillyaTrojan.Zbot.Win32.25258
TrendMicroTROJ_GEN.R002C0DB123
McAfee-GW-EditionGenericRXOR-HP!099231705D0E
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.099231705d0e9db2
SophosMal/MsilInj-C
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILPerseus.179529
JiangminTrojanSpy.MSIL.abi
WebrootW32.Autorun.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Spy]/MSIL.Zbot
XcitiumMalware@#ztc8z7g9gdld
ArcabitTrojan.MSILPerseus.D2BD49
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Autorun.ZG
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.C16381
Acronissuspicious
BitDefenderThetaAI:Packer.DF4FDDF61F
ALYacGen:Variant.MSILPerseus.179529
MAXmalware (ai score=99)
MalwarebytesMalware.AI.3921524389
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DB123
RisingWorm.Autorun!8.50 (CLOUD)
YandexTrojan.Agent!RDFbtVyMaGc
IkarusTrojan-Spy.MSIL
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/AntiAV.NET!tr
AVGMSIL:AutoRun-AF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Autorun.ZG?

Worm:Win32/Autorun.ZG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment