Malware

About “Win32/AutoRun.VB.AKT” infection

Malware Removal

The Win32/AutoRun.VB.AKT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AKT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AKT?


File Info:

name: 8DBB5A49FF75D18BA4D5.mlw
path: /opt/CAPEv2/storage/binaries/a04269d5645e2c275c0f035dfef09e20a4862084ddea50d5a7136ed7b3728e9b
crc32: 2EC9B598
md5: 8dbb5a49ff75d18ba4d566e993a457bb
sha1: a761f3deb5f5c39018071090e8eb9bb252cad587
sha256: a04269d5645e2c275c0f035dfef09e20a4862084ddea50d5a7136ed7b3728e9b
sha512: 85692f045ebbaa6c52f91dd6b198becad13c02becba342659886c293519161490f31d7ea7ba24802e6b46676f78eb79a90c0225b098a1b9ec7f7eaa8db24564a
ssdeep: 3072:iSeFqFzxgwMylAUR6UQUcJPPB5RPXsS+t9jiL4oQZiEzelyG:iqFzxgZVU49xEtlcWE/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175E3B32A7392F23AD815CAF8391982E094BDAC3625E26C17F7C25B1677F1C97D620713
sha3_384: e67a7e82e2f7bc161cb545ed9654a843221fb66d2b2ec06d28e8e8966ec30ce8ae288ff6f08d4330157c027c44b56073
ep_bytes: 68b4334000e8f0ffffff000000000000
timestamp: 2011-09-15 06:32:36

Version Info:

Translation: 0x0409 0x04b0
ProductName: gqhTtOVr
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ayRSUKMuKnvfmvCX
OriginalFilename: ayRSUKMuKnvfmvCX.exe

Win32/AutoRun.VB.AKT also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.95836
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.ba
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.95836
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.eb5f5c
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.Zyx.EF
SymantecW32.Changeup!gen35
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AKT
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dewj
BitDefenderTrojan.GenericKDZ.95836
NANO-AntivirusTrojan.Win32.Vobfus.cqkydo
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
EmsisoftTrojan.GenericKDZ.95836 (B)
F-SecureTrojan.TR/Diple.wekl
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMAC
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8dbb5a49ff75d18b
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.95836
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraTR/Diple.wekl
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D1765C
ZoneAlarmWorm.Win32.Vobfus.dewj
MicrosoftWorm:Win32/Vobfus.gen!N
VaristW32/Vobfus.V.gen!Eldorado
AhnLab-V3Trojan/Win32.Diple.R13793
Acronissuspicious
VBA32BScope.Trojan.Diple
ALYacTrojan.GenericKDZ.95836
TACHYONWorm/W32.Vobfus.151552.E
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAC
RisingWorm.Vobfus!1.99C7 (CLASSIC)
YandexTrojan.GenAsa!uuFslr38PCg
IkarusWorm.Win32.WBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaAI:Packer.F4976B2420
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/AutoRun.VB.AKT?

Win32/AutoRun.VB.AKT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment