Malware

About “Win32/AutoRun.VB.ABA” infection

Malware Removal

The Win32/AutoRun.VB.ABA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ABA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ABA?


File Info:

name: C845655FF1D0B813B0D7.mlw
path: /opt/CAPEv2/storage/binaries/75ad8a715dec1e0ba5e76d182c442666eba05cbf0f926786606458887ec32877
crc32: 50EE193B
md5: c845655ff1d0b813b0d72821cddae984
sha1: f4c0e7dbdd89e39bf8022760e0e86e59af91a0de
sha256: 75ad8a715dec1e0ba5e76d182c442666eba05cbf0f926786606458887ec32877
sha512: 068e7cd69161e345bc4e507312f9ebe1dc8401dddde8500de18b04d4bd120808c7a6016080edc04a2bab49a1401d2d05c39e117624fd29791f06ed390d0ba285
ssdeep: 1536:RoxBjIYKsZLyJxFdhXgI0TRQP/FY0Y6Y2YkYGYHRHNxtwv4RaoacXcmKdDwa:Y0YDpCH6QP/uRNBcF9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11693712B778010E7C95846B52DC3B7C715B62A851A273A835A203796FC75E020B7D9FF
sha3_384: ba247296a91619b4bf5d455fae561af846eb8fa7aa659e0fac282801cb044703cf85478dae6c964db315b2b0d9cf2e34
ep_bytes: 68a0124000e8eeffffff000000000000
timestamp: 2011-02-14 09:16:47

Version Info:

Translation: 0x0409 0x04b0
ProductName: GEQOXh
FileVersion: 4.38
ProductVersion: 4.38
InternalName: pGtFpi
OriginalFilename: pGtFpi.exe

Win32/AutoRun.VB.ABA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lkoQ
AVGWin32:VB-RED [Trj]
tehtrisGeneric.Malware
DrWebTrojan.Packed.21430
MicroWorld-eScanGen:Variant.Lazy.209946
FireEyeGeneric.mg.c845655ff1d0b813
CAT-QuickHealWorm.VobfusMF.S27814427
SkyhighBehavesLike.Win32.VBObfus.nt
ALYacGen:Variant.Lazy.209946
Cylanceunsafe
VIPREGen:Variant.Lazy.209946
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
AlibabaMalware:Win32/km_2f9164.None
K7GWTrojan-Downloader ( 001ff72a1 )
Cybereasonmalicious.ff1d0b
BitDefenderThetaAI:Packer.8D28449720
VirITTrojan.Win32.Generic.ATAM
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ABA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.VBNA.bsmw
BitDefenderGen:Variant.Lazy.209946
NANO-AntivirusTrojan.Win32.AutoRun.covjyr
AvastWin32:VB-RED [Trj]
TencentWorm.Win32.Vbna.kew
TACHYONTrojan/W32.VB-Krypt.94208.E
EmsisoftGen:Variant.Lazy.209946 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.AutoRun.cj
TrendMicroWORM_VOBFUS.SMIA
Trapminemalicious.moderate.ml.score
SophosW32/SillyFDC-FT
IkarusGen.Variant.VBKrypt
JiangminWorm/VBNA.gzmz
VaristW32/VB.BR.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.BB
XcitiumPacked.Win32.Krap.BV@2qqlmo
ArcabitTrojan.Lazy.D3341A
ViRobotTrojan.Win32.A.VBKrypt.94208.E
ZoneAlarmWorm.Win32.VBNA.bsmw
GDataGen:Variant.Lazy.209946
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R3045
McAfeeVBObfus.f
MAXmalware (ai score=81)
VBA32Trojan.VBRA.010801
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!JB/4NGU7+mE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/AutoRun.VB.ABA?

Win32/AutoRun.VB.ABA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment