Malware

Win32/AutoRun.VB.AKK malicious file

Malware Removal

The Win32/AutoRun.VB.AKK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AKK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.AKK?


File Info:

name: 2BE5366458309DE99CD4.mlw
path: /opt/CAPEv2/storage/binaries/255ed95b680ec91d6055f5688124d17b15c2cbf5a2bc0a968ed9e33e2bc596a0
crc32: 160587F1
md5: 2be5366458309de99cd42a61e385c233
sha1: f215aca6c3249484ab1bdc4a49d70993e9be28da
sha256: 255ed95b680ec91d6055f5688124d17b15c2cbf5a2bc0a968ed9e33e2bc596a0
sha512: ad6b5c564c26ab02f37d02e6177b2ddec2c043804ceee4c4acf181e6c038a34c85fa13d832326caa21f7e31348d359f78875d9cd54d1395869cb0b90a6dcf59d
ssdeep: 3072:HoOus4xfrd6YIeJjqP4yswNiqXiHiY8ZWfjF8Qh:HoPsQdJFePbswNiaiYAfRvh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C04F52A7691F23ACA19CAF47D5643E090BDAC3221D2AC17F7C22B1676F2D57D260713
sha3_384: 2c0e1822b2ec7c52e09b821dd683bddcb9d5444ea48cedc3cebe2f4d87fbcb4afca38e78a61abefb418e23d04a8c6977
ep_bytes: 68d8324000e8f0ffffff000000000000
timestamp: 2005-02-11 10:23:04

Version Info:

Translation: 0x0409 0x04b0
ProductName: sMeBFeGMFdbxjgQwJw
FileVersion: 1.00
ProductVersion: 1.00
InternalName: aXMgeigihxvkfoIJPE
OriginalFilename: aXMgeigihxvkfoIJPE.exe

Win32/AutoRun.VB.AKK also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.o!c
DrWebTrojan.VbCrypt.60
MicroWorld-eScanTrojan.GenericKDZ.97322
FireEyeGeneric.mg.2be5366458309de9
CAT-QuickHealTrojan.Vobfus.gen
McAfeeVBObfus.df
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2f34.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.458309
ArcabitTrojan.Generic.D17C2A
BitDefenderThetaAI:Packer.34AE04921F
VirITTrojan.Win32.SHeur4.TU
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AKK
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.bhs
BitDefenderTrojan.GenericKDZ.97322
NANO-AntivirusTrojan.Win32.Diple.cnwqdo
AvastWin32:VB-XRB [Trj]
RisingWorm.Vobfus!1.99C8 (CLASSIC)
TACHYONTrojan/W32.VB-Agent.176128.DS
EmsisoftTrojan.GenericKDZ.97322 (B)
F-SecureTrojan.TR/Spy.Agent.135168
BaiduWin32.Worm.Pronny.d
VIPRETrojan.GenericKDZ.97322
TrendMicroWORM_VOBFUS.SMAC
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.moderate.ml.score
SophosMal/VB-ABH
IkarusWorm.Win32.VBNA
GoogleDetected
AviraTR/Spy.Agent.135168
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
MicrosoftWorm:Win32/Autorun.ADB
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Dropper]
ZoneAlarmWorm.Win32.WBNA.bhs
GDataWin32.Trojan.PSE.10I69CR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R23097
Acronissuspicious
ALYacTrojan.GenericKDZ.97322
MAXmalware (ai score=87)
VBA32BScope.Trojan.Diple
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAC
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!hnsWsW5eEPo
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.VB.ceo
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-XRB [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.AKK?

Win32/AutoRun.VB.AKK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment