autorun.exe

AutoPlay Media Studio Runtime

The executable autorun.exe, “AutoPlay Application” has been detected as malware by 4 anti-virus scanners. This is a setup program which is used to install the application. This file is typically installed with the program Truckn Pro Training by Fog Line Software LLC. The file has been seen being downloaded from dl-mail.ymail.com.
Product:
AutoPlay Media Studio Runtime

Description:
AutoPlay Application

Version:
8.1.0.0

MD5:
44cab7e0694e9a91bdeeb8a81727e400

SHA-1:
f5275038d1d0a81b6e87e71a10d965c51cabeaac

SHA-256:
14e287bed1e643c4e30925732de3dcb730ef07fe5516709ceded3b8f1b50586b

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
12/23/2025 5:02:13 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
17284

Norman
Suspicious_Gen2.VKEGT
11.20140204

Reason Heuristics
Unnamed.Threat.27
14.3.11.12

VIPRE Antivirus
Trojan.Win32.Generic
23434

File size:
6.6 MB (6,880,256 bytes)

Product version:
8.1.0.0

Copyright:
Runtime Engine Copyright © 2012 Indigo Rose Corporation (www.indigorose.com)

Trademarks:
AutoPlay Media Studio is a Trademark of Indigo Rose Corporation

Original file name:
ams_runtime.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\autorun.exe

File PE Metadata
Compilation timestamp:
6/14/2012 9:10:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:Jt+UD05wK3zmGUN6XT+bwxHR1vj0pgFl6ZauVUeYI2i6oj9ghi1RebM390brVf/7:W605wKxUN8DhjXd8Uex6ojD390brV3pJ

Entry address:
0x2AED47

Entry point:
E8, 0D, 36, 01, 00, E9, 78, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 83, C4, F4, 9B, D9, 7D, FE, 9B, 66, 8B, 45, FE, 80, CC, 0C, 66, 89, 45, FC, D9, 6D, FC, DF, 7D, F4, D9, 6D, FE, 8B, 45, F4, 8B, 55, F8, C9, C3, 8B, FF, 55, 8B, EC, 51, 51, 57, 8D, 45, F8, 50, FF, 15, CC, 73, 84, 00, 6A, 01, 6A, 00, 6A, 00, FF, 75, FC, E8, 39, 9F, FF, FF, 2B, 05, A0, EB, 96, 00, 8B, 4D, F8, 1B, 15, A4, EB, 96, 00, 33, FF, 57, 03, C1, 68, 10, 27, 00, 00, 13, D7, 52, 50, E8, C7, BF...
 
[+]

Code size:
4.3 MB (4,478,464 bytes)

The file autorun.exe has been discovered within the following program.

Truckn Pro Training  by Fog Line Software LLC
www.FogLineSoftware.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file autorun.exe has been seen being distributed by the following URL.

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-UQHA0prHMusKwP__yaPFsIgJYa4hOPl5dBJp_Af99oTxTqz3O_BiioT6TeFf1eIRGH4nkLovJSeSm65J69qU1w/messages/@.id==APPkimIAABAjVylKYQpcWLEiZ2I/content/parts/@.id==2/raw?appid=YahooMailNeo&token=zitEzqOML3j84e6ealFTT5U7-km5qEQF52lp7AcCuBaKUQReGcAkEetWZTnB9eel_tmbZU_QP6bd5QzJLzvu9w&error=https://us-mg5.mail.yahoo.com/.../iframemsg?id=25d21f3b-a917-ccfd-8d18-2d1d67abaaea&ymreqid=3922afa5-e790-b8bd-01b4-7c0036010000

Remove autorun.exe - Powered by Reason Core Security