Worm

Worm:Win32/AutoRun!pz removal guide

Malware Removal

The Worm:Win32/AutoRun!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/AutoRun!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine Worm:Win32/AutoRun!pz?


File Info:

name: AF5A47A1EB9EB2EDA140.mlw
path: /opt/CAPEv2/storage/binaries/1797ace582cee23be308a33990af651e0f122bb7bbe67960a567525729ea8ac1
crc32: A0ED5A06
md5: af5a47a1eb9eb2eda1405ca9b0eedab4
sha1: edaa0f3b07a37a3bf11e94d98d31249c78a32ada
sha256: 1797ace582cee23be308a33990af651e0f122bb7bbe67960a567525729ea8ac1
sha512: 2f0c7e89a12ac5af0fb742478065b18db03ffb0768621037def352c2ffe82e2126a98a33a80bbd9301aa8f725212661ebfac618be18757fad01e766142bfc61d
ssdeep: 768:i3pE2H5/qtqSk5lT0ssO4oOLQ/0IyMLC6biv:i3NHwtqlEfw0IyMLC6ba
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB142A1FF3C06083D49F577155D692E6A6EBBA981F030A07A334622D9C3DF232D15386
sha3_384: b8c5bc51bb06b1699ec456673c374df37ce207f1a2c06ddd7269fe3410488777e074db1f58107734fdcde0f76ef27fc3
ep_bytes: 68d0174000e8f0ffffff000048000000
timestamp: 2010-01-31 01:14:52

Version Info:

Translation: 0x0409 0x04b0
CompanyName: NVIDIA Corporation 53722646459
ProductName: noympvbls
FileVersion: 1.00
ProductVersion: 1.00
InternalName: 30
OriginalFilename: 30.exe

Worm:Win32/AutoRun!pz also known as:

BkavW32.AutorunQKD.Fam.Worm
LionicTrojan.Win32.VBKrypt.lP2U
MicroWorld-eScanGen:Variant.Lazy.210641
FireEyeGeneric.mg.af5a47a1eb9eb2ed
CAT-QuickHealWorm.Autorun.WZ4
SkyhighW32/Autorun.worm.bbm
McAfeeW32/Autorun.worm.bbm
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 001c26381 )
AlibabaWorm:Win32/Autorun.f3e2522c
K7GWEmailWorm ( 001c26381 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWorm.Win32.VB.BI
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.LQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Esfury-9371334-0
KasperskyWorm.Win32.VBNA.appj
BitDefenderGen:Variant.Lazy.210641
NANO-AntivirusTrojan.Win32.VB.bwabz
AvastWin32:VB-OJK [Trj]
EmsisoftGen:Variant.Lazy.210641 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner1.18487
VIPREGen:Variant.Lazy.210641
TrendMicroMal_Banker
Trapminesuspicious.low.ml.score
SophosMal/VBCheMan-A
IkarusVirus.Win32.VB
JiangminWorm/VBNA.gzoz
WebrootW32.Vobfusworm.Gen
VaristW32/AutoRun.R.gen!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=100)
Antiy-AVLWorm/Win32.VBNA.appj
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/AutoRun!pz
XcitiumTrojWare.Win32.Autorun.JT@4zqndt
ArcabitTrojan.Lazy.D336D1
ZoneAlarmWorm.Win32.VBNA.appj
GDataWin32.Worm.Autorun.Y
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R1977
BitDefenderThetaGen:NN.ZevbaF.36744.mq3@aChLzMmi
ALYacGen:Variant.Lazy.210641
VBA32Trojan.VBRA.02146
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallMal_Banker
RisingTrojan.DL.Pux.d (CLASSIC)
YandexTrojan.GenAsa!gQJVj+XfME0
SentinelOneStatic AI – Malicious PE
FortinetW32/VB.JT!tr
AVGWin32:VB-OJK [Trj]
Cybereasonmalicious.b07a37
DeepInstinctMALICIOUS

How to remove Worm:Win32/AutoRun!pz?

Worm:Win32/AutoRun!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment