Worm

Worm:Win32/AutoRun!atmn information

Malware Removal

The Worm:Win32/AutoRun!atmn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/AutoRun!atmn virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Reads data out of its own binary image
  • ‘Dropbox’ in HTML Title but connection is not HTTPS. Possibly indicative of phishing.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics
  • Contains RAT configuration for DarkComet (see Static Analysis tab)

Related domains:

z.whorecord.xyz
a.tomx.xyz
xred.mooo.com
freedns.afraid.org
ocsp.pki.goog
doc-14-14-docs.googleusercontent.com
www.dropbox.com
ocsp.digicert.com
xred.site50.net
www.000webhost.com
ocsp.comodoca.com

How to determine Worm:Win32/AutoRun!atmn?


File Info:

crc32: 49783647
md5: e85965a416297e42529e543082e768db
name: eewqewqe.exe
sha1: 63183601121650f80f85cbaf6c561c68613a5001
sha256: 2b959cad110bb477bfa1cfae45927c3d02fe5eab7043d8d67f71e2d5d054c446
sha512: b6783897b060391c256a82ceac32e88bff83c2dc0faafff2c1cda83311af4b031c0921df8b6702ce2e22b9569812b635913070dde75cd823450fec056e93ee78
ssdeep: 24576:knsJ39LyjbJkQFMhmC+6GD9oJxZ1xuVVjfFoynPaVBUR8f+kN10EBM:knsHyjtk2MYC5GD6JLQDgok30b
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.5
CompanyName: Synaptics
LegalTrademarks:
Comments: Modified by an unpaid evaluation copy of Resource Tuner 2. http://www.heaventools.com
ProductName: RIP crack dragonjin
ProductVersion: 1.0.0.0
FileDescription: dragon yt crack rip
OriginalFilename:
Translation: 0x041f 0x04e6

Worm:Win32/AutoRun!atmn also known as:

BkavW32.AIDetectVM.malware1
ClamAVWin.Trojan.DarkKomet-1
FireEyeGeneric.mg.e85965a416297e42
CAT-QuickHealSus.Nocivo.E0011
McAfeeGenericRXJO-YL!E85965A41629
CylanceUnsafe
ZillyaTrojan.Delf.Win32.76144
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderMemScan:Trojan.Inject.AUZ
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.416297
Invinceaheuristic
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Zorex.A
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
CynetMalicious (score: 100)
GDataMemScan:Trojan.Inject.AUZ
KasperskyBackdoor.Win32.DarkKomet.hqxy
AlibabaBackdoor:Win32/DarkKomet.131
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
MicroWorld-eScanMemScan:Trojan.Inject.AUZ
RisingBackdoor.Darkcomet!8.1117F (C64:YzY0Oj52fHJs/ABu)
Endgamemalicious (high confidence)
EmsisoftMemScan:Trojan.Inject.AUZ (B)
ComodoVirus.Win32.Agent.DE@74b38h
F-SecureTrojan:W97M/MaliciousMacro.GEN
DrWebTrojan.DownLoader22.9658
VIPREBehavesLike.Win32.Malware.eah (mx-v)
TrendMicroVirus.Win32.NAPWHICH.B
Trapminesuspicious.low.ml.score
SophosTroj/Backdr-ID
SentinelOneDFI – Malicious PE
CyrenW32/Backdoor.OAZM-5661
JiangminTrojan.Generic.bhoqf
WebrootW32.Malware.gen
AviraBDS/DarkKomet.GS
MAXmalware (ai score=82)
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet.xyk
MicrosoftWorm:Win32/AutoRun!atmn
ArcabitHEUR.VBA.Trojan.d
SUPERAntiSpywareBackdoor.DarkKomet/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
BitDefenderThetaAI:Packer.E73B3AD321
ALYacMemScan:Trojan.Inject.AUZ
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
ZonerTrojan.Win32.88102
ESET-NOD32Win32/Delf.NBX
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
TencentVirus.Win32.DarkKomet.a
YandexTrojan.Comet.Gen.LO
IkarusVirus.Win32.Delf
eGambitRAT.DarkComet
FortinetW32/Delf.NBX!tr
Ad-AwareMemScan:Trojan.Inject.AUZ
AVGMSIL:GenMalicious-CHX [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM41.1.51BB.Malware.Gen

How to remove Worm:Win32/AutoRun!atmn?

Worm:Win32/AutoRun!atmn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment