Malware

Should I remove “Win32/AutoRun.VB.AJP”?

Malware Removal

The Win32/AutoRun.VB.AJP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AJP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AJP?


File Info:

name: A38214C7B2B3D550DFD1.mlw
path: /opt/CAPEv2/storage/binaries/a4e32414f3568cd29b5f5442e0bedd7b81a3d1bcb949ffb6ee36e73ff5650c2f
crc32: 2BB74A5D
md5: a38214c7b2b3d550dfd1da38c3fb4413
sha1: 916fe0b1b6688cb09f9ebe3da32a5bcefcd42d3c
sha256: a4e32414f3568cd29b5f5442e0bedd7b81a3d1bcb949ffb6ee36e73ff5650c2f
sha512: 9d81fd91807a11211f9d1bc5703aa5a01dbe9a0cd79f9fdbdcf8c0e01b8e1dfd85fda7e857edc4bcb6c279ab6e8809b3cca50aae86bfbb051f25a522e32442c1
ssdeep: 3072:RaPi07+GPzGUv9mvS4O8aR3krDbVqz2shG+5O:Rw7pi2I64O7R3UhO2sh/E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DD3832E7290E67ED426CBF83D1A47A0806DAC3521D5AD03F7C24F16B6F1E9B9221753
sha3_384: b3bc1b4abb96dd646186ab2ddffff05e3eccf238ea3eeb89d66df1521fd923c59ebd85faa69e29850cd5493d6cb7169f
ep_bytes: 6850394000e8f0ffffff000048000000
timestamp: 2011-08-10 07:39:51

Version Info:

Translation: 0x0409 0x04b0
ProductName: jnlGrVWhDeYp
FileVersion: 1.00
ProductVersion: 1.00
InternalName: jzsgSFglEagtTmeFVIXJ
OriginalFilename: jzsgSFglEagtTmeFVIXJ.exe

Win32/AutoRun.VB.AJP also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Heur.Conjar.1
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.g
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.7b2b3d
BaiduWin32.Worm.Pronny.d
VirITWorm.Win32.WBNA.AWQ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AJP
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMHE
ClamAVWin.Packed.Score-7640427-0
KasperskyWorm.Win32.Vobfus.drru
BitDefenderGen:Heur.Conjar.1
NANO-AntivirusTrojan.Win32.VBKrypt.cmxpwi
AvastWin32:Renos-BIJ [Trj]
TACHYONTrojan/W32.VB-Krypt.135170
SophosMal/SillyFDC-T
GoogleDetected
F-SecureTrojan.TR/Dropper.VB.Gen
DrWebTrojan.VbCrypt.60
VIPREGen:Heur.Conjar.1
TrendMicroWORM_VOBFUS.SMHE
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.a38214c7b2b3d550
EmsisoftGen:Heur.Conjar.1 (B)
IkarusWorm.Gamarue
VaristW32/Vobfus.W.gen!Eldorado
AviraTR/Dropper.VB.Gen
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.DA
ArcabitTrojan.Conjar.1
ViRobotTrojan.Win32.A.VBKrypt.135168.CQ
ZoneAlarmWorm.Win32.Vobfus.drru
GDataGen:Heur.Conjar.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R124105
Acronissuspicious
VBA32Trojan.Varydrop.1392
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Win32.VBCode.fmo (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.G!tr
BitDefenderThetaAI:Packer.18C2E7CA20
AVGWin32:Renos-BIJ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/AutoRun.VB.AJP?

Win32/AutoRun.VB.AJP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment