Trojan

Trojan.VB.Autorun.AF (file analysis)

Malware Removal

The Trojan.VB.Autorun.AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VB.Autorun.AF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.VB.Autorun.AF?


File Info:

name: D64AED4B051E63DE8C5A.mlw
path: /opt/CAPEv2/storage/binaries/9a9ff55908a8bdd3e36447079c321d2809300af1050ee6e10bacd705ad53cd44
crc32: 6D6C2D53
md5: d64aed4b051e63de8c5a4c5923fe8ab0
sha1: bca0f4190ac467048bdadde0e5fbff637387354f
sha256: 9a9ff55908a8bdd3e36447079c321d2809300af1050ee6e10bacd705ad53cd44
sha512: 2d5a24e0784b48a214836807f743f9c2e31f19154d934977105d1b041847416ff82cc18f134b89a65bc3dbe908c666f63c5c8edc825fe0c14ba9b6218647fa4d
ssdeep: 12288:9PIRAA+8PBV378FE+2VSBnr5IssZFBV84df:vJ8PvIe7SBnr5funf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC840203F724C611C5140B71856BEBC72E3DED66D9528B233AE1F02E2DB27E5661298F
sha3_384: 53be121522454406ab11612a450e3d4d3834317f9524a042723ba72b01730a963cd2f2ec3a6f19012ebf36b4bf40c378
ep_bytes: 60be006040008dbe00b0ffff57eb0b90
timestamp: 2008-06-01 21:58:02

Version Info:

0: [No Data]

Trojan.VB.Autorun.AF also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.VB.Autorun.AF
FireEyeGeneric.mg.d64aed4b051e63de
CAT-QuickHealTrojan.AgentMF.S26355867
ALYacTrojan.VB.Autorun.AF
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.VB.Autorun.AF
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005327171 )
K7GWEmailWorm ( 005327171 )
Cybereasonmalicious.b051e6
BaiduWin32.Worm.VB.g
SymantecW32.Bluven
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AMP
APEXMalicious
AvastWin32:Evo-gen [Trj]
ClamAVWin.Malware.Score-6830630-0
KasperskyTrojan.Win32.VB.enm
BitDefenderTrojan.VB.Autorun.AF
NANO-AntivirusTrojan.Win32.VB.cqkxjh
TencentWorm.Win32.Autorun.aar
EmsisoftTrojan.VB.Autorun.AF (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen3.63843
SophosTroj/VBDrpB-Gen
SentinelOneStatic AI – Malicious PE
JiangminTrojan/VB.ckgb
VaristW32/FakeDoc.CE.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.VB
Kingsoftmalware.kb.b.914
XcitiumWorm.Win32.Autorun.h0@143j1r
ArcabitTrojan.VB.Autorun.AF
ViRobotTrojan.Win32.VB.113692[UPX]
ZoneAlarmTrojan.Win32.VB.enm
GDataTrojan.VB.Autorun.AF
CynetMalicious (score: 100)
Acronissuspicious
McAfeeW32/Autorun.worm.ie
VBA32Trojan.VB
Cylanceunsafe
PandaGeneric Suspicious
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
YandexTrojan.GenAsa!WzfYyst7b2g
IkarusWorm.Win32.AutoRun
FortinetW32/VB.ENM!tr
BitDefenderThetaAI:Packer.A53D69471D
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.VB.Autorun.AF?

Trojan.VB.Autorun.AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment