Malware

Win32/AutoRun.VB.AJP (file analysis)

Malware Removal

The Win32/AutoRun.VB.AJP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AJP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AJP?


File Info:

name: 3A44CE721AA60520D140.mlw
path: /opt/CAPEv2/storage/binaries/b3035905e0f4118c19ff5593544177c57d7801b2e6e52acd5c42433858b4154e
crc32: CD071F42
md5: 3a44ce721aa60520d14009c3f531637b
sha1: 9b717f85c4b0eade509a00dd82a12a072014bec3
sha256: b3035905e0f4118c19ff5593544177c57d7801b2e6e52acd5c42433858b4154e
sha512: 39ade314c50c8ce5d54a2ccd460d06f122aaf69bbe722b490f6c2e8dd49f342ba4e6593c37c44eb4f0010e7a61bdcf44deaab4cdec87dcaff05cdf801bd7ad0b
ssdeep: 3072:R6l3Ui07+GPzGUv9mvS4O8aR3krDbVqz2shG+gK:R6l3U7pi2I64O7R3UhO2sh/l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9D3722E7690F67ED426CBF82D1A47A0806DAC3421D5AD03F7C24F16B6F1E9B9221753
sha3_384: bc41933381f69febb9a1857a9c37882ac80018015e43bb40d4e2dfa882fe9641422253ab92f23d32106600566f520f46
ep_bytes: 6850394000e8f0ffffff000048000000
timestamp: 2011-08-10 07:39:51

Version Info:

Translation: 0x0409 0x04b0
ProductName: BzTSyhXNJIAA
FileVersion: 1.00
ProductVersion: 1.00
InternalName: AnCwyyjxRRancAoGXBwG
OriginalFilename: AnCwyyjxRRancAoGXBwG.exe

Win32/AutoRun.VB.AJP also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Heur.Conjar.1
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.g
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Conjar.1
BaiduWin32.Worm.Pronny.d
VirITWorm.Win32.WBNA.AWQ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AJP
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMHE
ClamAVWin.Packed.Score-7640427-0
KasperskyWorm.Win32.Vobfus.drru
BitDefenderGen:Heur.Conjar.1
NANO-AntivirusTrojan.Win32.VBKrypt.cmxpwi
AvastWin32:Renos-BIJ [Trj]
TencentWin32.Worm.Vobfus.Bplw
EmsisoftGen:Heur.Conjar.1 (B)
F-SecureTrojan.TR/Dropper.VB.Gen
DrWebTrojan.VbCrypt.60
VIPREGen:Heur.Conjar.1
TrendMicroWORM_VOBFUS.SMHE
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.3a44ce721aa60520
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
GoogleDetected
AviraTR/Dropper.VB.Gen
VaristW32/Vobfus.W.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.DA
ViRobotTrojan.Win32.A.VBKrypt.135168.CQ
ZoneAlarmWorm.Win32.Vobfus.drru
GDataGen:Heur.Conjar.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R124105
Acronissuspicious
BitDefenderThetaAI:Packer.18C2E7CA20
VBA32Trojan.Varydrop.1392
Cylanceunsafe
PandaW32/VobfusLNK.A
RisingTrojan.Win32.VBCode.fmo (CLASSIC)
YandexTrojan.GenAsa!WyeBgXFQvgI
IkarusWorm.Gamarue
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.G!tr
AVGWin32:Renos-BIJ [Trj]
Cybereasonmalicious.21aa60
DeepInstinctMALICIOUS
alibabacloudWorm.Win.Vobfus.8d3fdeab

How to remove Win32/AutoRun.VB.AJP?

Win32/AutoRun.VB.AJP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment