Worm

Worm:Win32/AutoRun!pz removal instruction

Malware Removal

The Worm:Win32/AutoRun!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/AutoRun!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Worm:Win32/AutoRun!pz?


File Info:

name: 52D5C89053EC334C16A6.mlw
path: /opt/CAPEv2/storage/binaries/82ac7e74ba8ad737136db85defe8a7ac6c9fe81f788a6534d3fb0a35a4c053b6
crc32: 9B9308EA
md5: 52d5c89053ec334c16a6392df15a1fb9
sha1: 43d3bcaf523043951c8e02c455d2c4d972eb2c4e
sha256: 82ac7e74ba8ad737136db85defe8a7ac6c9fe81f788a6534d3fb0a35a4c053b6
sha512: 8f1a5ca2db353ab4abcd87ded2b4672d0ba3a7c403c64bcaa42dc640157f1b47332738864ba976090abff41da1aa763e34ef297f2a352892910b33577b1fbe89
ssdeep: 6144:cf+Jjjou35J6i5plrzuo6/LkeYvjoIHnv0RX/VwFdLD/7MsrYMC+9GXL9M8sG3d+:bj8u3ui5pl+uBvc/V0FdYxJdRqMy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129A46D32F3F19433D1331A788D5B93AC982ABE113D28A8467BE91D4C5F39791742B297
sha3_384: 572a547a075aae40f292571d262341ebd76b0cda2ca071726ce368118e8d5c5276b99ff7356803015d63d2c1f27b5ff3
ep_bytes: 558bec83c4f0b850554600e8fc18faff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Worm:Win32/AutoRun!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.6D934B1C.A.470D9B3B
CAT-QuickHealWorm.Autorun.RE8
SkyhighBehavesLike.Win32.Autorun.gh
ALYacGeneric.Dacic.6D934B1C.A.470D9B3B
Cylanceunsafe
ZillyaWorm.AutoRun.Win32.550
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005726171 )
BitDefenderGeneric.Dacic.6D934B1C.A.470D9B3B
K7GWTrojan ( 005726171 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitGeneric.Dacic.6D934B1C.A.470D9B3B
BitDefenderThetaGen:NN.ZelphiF.36744.DGW@a0HKHFhi
VirITWorm.Win32.AutoRun.PFS
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.Delf.J
APEXMalicious
ClamAVWin.Worm.Autorun-314
KasperskyTrojan.Win32.Fsysna.dhqm
NANO-AntivirusTrojan.Win32.AutoRun.dzjjvz
AvastWin32:AutoRun-AOY [Wrm]
TACHYONWorm/W32.DP-AutoRun.483840
EmsisoftGeneric.Dacic.6D934B1C.A.470D9B3B (B)
BaiduWin32.Worm.Autorun.s
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.Winlock.14301
VIPREGeneric.Dacic.6D934B1C.A.470D9B3B
TrendMicroMal_Otorun5
FireEyeGeneric.mg.52d5c89053ec334c
SophosMal/SillyFDC-A
SentinelOneStatic AI – Malicious PE
JiangminWorm/AutoRun.kjd
GoogleDetected
AviraDR/Delphi.Gen
VaristW32/AutoRun.AD.gen!Eldorado
Antiy-AVLWorm/Win32.AutoRun
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.AutoRun.~ZP@2mkay
MicrosoftWorm:Win32/AutoRun!pz
ZoneAlarmTrojan.Win32.Fsysna.dhqm
GDataWin32.Worm.Autorun.AM
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AutoRun.C65764
McAfeeW32/Autorun.worm.zi
MAXmalware (ai score=82)
VBA32TScope.Trojan.Delf
MalwarebytesDelphi.Worm.AutoRun.DDS
PandaGeneric Malware
TrendMicro-HouseCallMal_Otorun5
RisingWorm.Autorun!1.9D28 (CLASSIC)
YandexWorm.AutoRun!+0fcOBtSu8Q
IkarusWorm.Win32.AutoRun
FortinetW32/Autorun.DJ!worm
AVGWin32:AutoRun-AOY [Wrm]
Cybereasonmalicious.f52304
DeepInstinctMALICIOUS

How to remove Worm:Win32/AutoRun!pz?

Worm:Win32/AutoRun!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment