Worm

Worm:Win32/AutoRun!pz removal instruction

Malware Removal

The Worm:Win32/AutoRun!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/AutoRun!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/AutoRun!pz?


File Info:

name: CC90025C0F1D2715BAED.mlw
path: /opt/CAPEv2/storage/binaries/4d9b254646fa394b1eddb96ae2d29929cfe6562ad24539610f6211f7394ae1b0
crc32: 6812C060
md5: cc90025c0f1d2715baedac9ac160d878
sha1: 1636f122d8b11ae33a6ddd8a045747c05334c840
sha256: 4d9b254646fa394b1eddb96ae2d29929cfe6562ad24539610f6211f7394ae1b0
sha512: 19eefd6e81947207f2176d67cb3606a167a6b84aad48570e0f642ae33eee4dd8894b65ec9c88e96f41c6debba96657a207e7ebcca48c70195a10784e6d8e6737
ssdeep: 49152:y5CPEkm/Jpp4o/o/ae0U8CnAzhxLF1s0r/QMl+xcyQZ5eTuoVf2I9yBNqgUrzguD:Q4o/o/ae0U8CnAzhxLF1s0r/QMl+xcyX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14CA58D12F68280B2E616153011B75739AB34DB565E259BB3F3ACDCB83F326719A3324D
sha3_384: 0c205c3bac1b834a4c6a829255590f12020bc6d37c206774b3be4134e1060b143d12c399f39775e38a8499161ec2a731
ep_bytes: 558bec6aff6858395d00682050540064
timestamp: 2022-12-15 16:38:38

Version Info:

FileVersion: 1.0.0.0
FileDescription: 用户端
ProductName: 用户端
ProductVersion: 1.0.0.0
CompanyName: 用户端
LegalCopyright: 用户端
Comments: 用户端
Translation: 0x0804 0x04b0

Worm:Win32/AutoRun!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
ClamAVWin.Malware.Trojanx-9951053-0
FireEyeGeneric.mg.cc90025c0f1d2715
SkyhighBehavesLike.Win32.Generic.vh
McAfeeGenericRXAA-AA!CC90025C0F1D
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.2d8b11
BitDefenderThetaGen:NN.ZexaF.36744.es0@aSDW45bH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:MalwareX-gen [Trj]
RisingWorm.AutoRun!8.50 (CLOUD)
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DBG24
IkarusTrojan.Crypt
GDataWin32.Trojan.PSE.1MVF8WB
GoogleDetected
Antiy-AVLRiskWare/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftWorm:Win32/AutoRun!pz
VaristW32/OnlineGames.HG.gen!Eldorado
AhnLab-V3Trojan/Win.MalwareX-gen.C5330896
VBA32BScope.Backdoor.BlackHole
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DBG24
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Worm:Win32/AutoRun!pz?

Worm:Win32/AutoRun!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment