Malware

Win32/AutoRun.VB.ABC (file analysis)

Malware Removal

The Win32/AutoRun.VB.ABC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ABC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/AutoRun.VB.ABC?


File Info:

name: 4A8B1221304C963DA8AE.mlw
path: /opt/CAPEv2/storage/binaries/c84d01673d4712a00c4b5c0b18668bfa5bdaa69d0970bc9145584e00d2ef23a6
crc32: 33BFECD3
md5: 4a8b1221304c963da8ae9aa282846234
sha1: 9cd43b2885b21fd46f6512f5a562e96acd632497
sha256: c84d01673d4712a00c4b5c0b18668bfa5bdaa69d0970bc9145584e00d2ef23a6
sha512: 99251890a77f587926bfd05ec15294f8b91502d9e1065160ff7ef887cf15b9642eed4bf64235e5d59b59559fddf7d5e43fe7d3f2f306a79b696a67004180600b
ssdeep: 1536:0cxBv6uZm6rxxU4XgI0TcaP/FY0Y6Y2YkYGYVMktdRHNxtwv4Raoac6cmKde9a:7vhYA5XaP/iRN0cIk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B93712B778010E7D95846B52DC3BBC715B63A850A273A835A203796FC65E020B7D9FF
sha3_384: 9f6e52ae4919fae91bfd696217235debf5de99e60df7dd33c5c5bd0541d45068862fa234b4adb727ee499a6dfac6353f
ep_bytes: 68a0124000e8eeffffff000000000000
timestamp: 2011-02-14 09:21:39

Version Info:

Translation: 0x0409 0x04b0
ProductName: xjxVhl
FileVersion: 7.43
ProductVersion: 7.43
InternalName: CijAZX
OriginalFilename: CijAZX.exe

Win32/AutoRun.VB.ABC also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Packed.21430
MicroWorld-eScanGen:Variant.Barys.431091
FireEyeGeneric.mg.4a8b1221304c963d
CAT-QuickHealWorm.VobfusMF.S27814427
McAfeeVBObfus.f
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Barys.431091
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
AlibabaWorm:Win32/Vobfus.029966d8
K7GWTrojan-Downloader ( 001ff72a1 )
Cybereasonmalicious.1304c9
BitDefenderThetaAI:Packer.AB640DBB20
VirITTrojan.Win32.Generic.ATAM
CyrenW32/VB.BR.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.ABC
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.VBNA.bsmw
BitDefenderGen:Variant.Barys.431091
NANO-AntivirusTrojan.Win32.AutoRun.flwcbg
ViRobotTrojan.Win32.A.VBKrypt.94208.E
AvastWin32:VB-RED [Trj]
EmsisoftGen:Variant.Barys.431091 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Autorun.ac
ZillyaTrojan.VBKrypt.Win32.60235
TrendMicroWORM_VOBFUS.SMIA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nt
Trapminemalicious.moderate.ml.score
SophosW32/SillyFDC-FT
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.431091
JiangminWorm/VBNA.hfbt
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumPacked.Win32.Krap.BV@2qqlmo
ArcabitTrojan.Barys.D693F3
ZoneAlarmWorm.Win32.VBNA.bsmw
MicrosoftWorm:Win32/Vobfus.BB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R3045
VBA32Trojan.VBRA.010801
ALYacGen:Variant.Barys.431091
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!JB/4NGU7+mE
IkarusGen.Variant.VBKrypt
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-RED [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/AutoRun.VB.ABC?

Win32/AutoRun.VB.ABC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment