Worm

Worm:Win32/AutoRun!pz removal guide

Malware Removal

The Worm:Win32/AutoRun!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/AutoRun!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Worm:Win32/AutoRun!pz?


File Info:

name: 4A34F7AE99BAFFEEF14E.mlw
path: /opt/CAPEv2/storage/binaries/b00f259d3ccb79d9ace9c0b7d7a9250c52907b7f2c50b1320386a6db9efbfd22
crc32: 66AD81D6
md5: 4a34f7ae99baffeef14ecd520d5da8d2
sha1: 4d4039ddccb977dd5eab4e71a581cd33e87bea3a
sha256: b00f259d3ccb79d9ace9c0b7d7a9250c52907b7f2c50b1320386a6db9efbfd22
sha512: d56d1abf210df66deba6f42a6e63942f86299689558b931b74639f1f406b5056c2bd691f2aa704c7e7d05df8a80588494839647c0b6f14e77a55ed98d244aea5
ssdeep: 6144:EBapC9DUIYmO5Kv5Q7X/l/rYvkW1VxxfnzrV9UAH0ctkPfc92F8+HLpIh9jhl:zpQD+mO5KWy/zrVbt4fcY7H9U9jv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195A46C32A2F09437D1732B7C8D5BA6AC98267E103D28B8476BE91D4C5F3D781752B293
sha3_384: 8ecc3db3607ebed18b8ed14adc7de04edc7465d165a12ffda643152afb1a30d9b451989f13ea272c4dd12979187faddb
ep_bytes: 558bec83c4f0b840174600e87456faff
timestamp: 2006-08-28 01:16:55

Version Info:

0: [No Data]

Worm:Win32/AutoRun!pz also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.AutoRun.lmnK
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.6D934B1C.A.A3F6C4BC
FireEyeGeneric.mg.4a34f7ae99baffee
CAT-QuickHealWorm.Autorun.RE8
SkyhighBehavesLike.Win32.Autorun.gh
McAfeeW32/Autorun.worm.br
MalwarebytesDelphi.Worm.AutoRun.DDS
ZillyaWorm.AutoRun.Win32.2488
SangforTrojan.Win32.Save.a
K7AntiVirusP2PWorm ( 000630621 )
AlibabaWorm:Win32/AutoRun.233b43a9
K7GWP2PWorm ( 000630621 )
Cybereasonmalicious.e99baf
BaiduWin32.Worm.Autorun.s
VirITWorm.Win32.AutoRun.DBXP
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.Delf.DE
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_048811.TOMB
ClamAVWin.Worm.Autorun-314
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Dacic.6D934B1C.A.A3F6C4BC
NANO-AntivirusTrojan.Win32.AutoRun.bynqc
AvastWin32:AutoRun-AOY [Wrm]
TencentTrojan.Win32.Autorun.wc
TACHYONTrojan/W32.DP-Agent.471552.M
EmsisoftGeneric.Dacic.6D934B1C.A.A3F6C4BC (B)
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.DownLoad.30734
VIPREGeneric.Dacic.6D934B1C.A.A3F6C4BC
TrendMicroTROJ_AGENT_048811.TOMB
SophosMal/SillyFDC-A
IkarusWorm.Win32.AutoRun
JiangminWorm/AutoRun.zum
WebrootW32.Worm.Autorun.Gen
GoogleDetected
AviraDR/Delphi.Gen
VaristW32/AutoRun.AS.gen!Eldorado
Antiy-AVLWorm/Win32.AutoRun
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/AutoRun!pz
XcitiumWorm.Win32.AutoRun.~AIN@58y89
ArcabitGeneric.Dacic.6D934B1C.A.A3F6C4BC
ViRobotWorm.Win32.Autorun.465408
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Worm.Autorun.AM
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Autorun.R638395
Acronissuspicious
VBA32Trojan.Delf.Autorun.0415
ALYacGeneric.Dacic.6D934B1C.A.A3F6C4BC
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.32639
RisingWorm.Autorun!1.9D28 (CLASSIC)
YandexTrojan.GenAsa!9k+zEyzUElM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/AutoRun.QGG!worm
BitDefenderThetaGen:NN.ZelphiF.36802.CGW@a4UmAAoi
AVGWin32:AutoRun-AOY [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Delf.f5b60770

How to remove Worm:Win32/AutoRun!pz?

Worm:Win32/AutoRun!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment