Malware

Win32/AutoRun.VB.ADY (file analysis)

Malware Removal

The Win32/AutoRun.VB.ADY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ADY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ADY?


File Info:

name: 1084E24419A7E897502C.mlw
path: /opt/CAPEv2/storage/binaries/3b41133750d1328691960c5c145c6d6c0682795c409f1829c24f1ee0d41b8284
crc32: D3AE8605
md5: 1084e24419a7e897502c07bd637c30ad
sha1: 4da19125d1e41b2ca4a1c8f43de74d1f18923b0c
sha256: 3b41133750d1328691960c5c145c6d6c0682795c409f1829c24f1ee0d41b8284
sha512: 4ce58038ca7fb6db9d5d20faf3be55d5fc1a8c6412b6026b99dfef3f8ba2284f99536c813d7c95a6570ab471ee7ba5d7fdde738170b0292e6ad50f3677663197
ssdeep: 3072:+crmzTIn1x193iAmWmHSEDMehogxgbDT5qouy57UgZgkaDqKEmvqsgAXN:+UVUAmWmHSEDMehogxgbDTQouy5YgZgF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T120045316EA54A06BE052D4F17529C27B791A3D361790AC53B781EF16A1722FBB8F030F
sha3_384: c21b317d77e1f38b84687b2470ac5d492b59ebd5e12cb67ed38a0207c74a7497ea8e345e2e7ee27f1c05126f8a5e187e
ep_bytes: 68243f4000e8eeffffff000000000000
timestamp: 2011-04-15 16:19:51

Version Info:

Translation: 0x0409 0x04b0
ProductName: yHEVwKTiMBgJs
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ZIefTdPEEJrzgPfqxApC
OriginalFilename: ZIefTdPEEJrzgPfqxApC.exe

Win32/AutoRun.VB.ADY also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Heur.Conjar.1
ClamAVWin.Malware.Vobfus-9814633-0
SkyhighBehavesLike.Win32.Generic.cm
McAfeeVBObfus.n
Cylanceunsafe
ZillyaWorm.WBNA.Win32.469740
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.5d1e41
BitDefenderThetaAI:Packer.254A2CEF15
VirITTrojan.Win32.SHeur3.BUUT
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.ADY
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Heur.Conjar.1
NANO-AntivirusTrojan.Win32.Chinky.hgtklw
AvastWin32:VB-TER [Drp]
TencentWorm.Win32.WBNA.hk
EmsisoftGen:Heur.Conjar.1 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Chinky.AB
DrWebTrojan.VbCrypt.60
VIPREGen:Heur.Conjar.1
TrendMicroWORM_VOBFUS.SMKV
FireEyeGeneric.mg.1084e24419a7e897
SophosMal/VB-ABH
IkarusTrojan.Win32.VBKrypt
GDataGen:Heur.Conjar.1
GoogleDetected
AviraTR/Chinky.AB
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Vobfus.DC@6lfi1w
ArcabitTrojan.Conjar.1
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftWorm:Win32/Vobfus.gen!J
VaristW32/Vobfus.W.gen!Eldorado
Acronissuspicious
VBA32BScope.Trojan.Diple
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Suspicious
TrendMicro-HouseCallWORM_VOBFUS.SMKV
RisingWorm.VobfusEx!1.99E1 (CLASSIC)
YandexTrojan.GenAsa!ZoVlaH5ohfw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.ADV!tr
AVGWin32:VB-TER [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/AutoRun.VB.ADY?

Win32/AutoRun.VB.ADY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment