Malware

Win32/AutoRun.VB.AKT (file analysis)

Malware Removal

The Win32/AutoRun.VB.AKT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AKT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AKT?


File Info:

name: BA5ABA1DAFCA15892057.mlw
path: /opt/CAPEv2/storage/binaries/f36d0862dbfc242b5679cfd3c04a249c6b334ed4b1a775bd5c8272f3e34151b9
crc32: 90B6EAA2
md5: ba5aba1dafca1589205700e3c16c55f4
sha1: bf77323fd42b734441ddb03bb9a9aa1b6ce231c7
sha256: f36d0862dbfc242b5679cfd3c04a249c6b334ed4b1a775bd5c8272f3e34151b9
sha512: d63591990f4b84894f8972074f9d8069b7cdbe090f7da467ea98ca781e99de35948fa32738451553d9b3182c911bfefdc73ef23a441639f5c23fc545f496b89e
ssdeep: 3072:93yIpK9xKA9w2p4QZisLaazNiLhkyy4Y4oQZiEZVH:93hpKxY+1isuazgtklVWX1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15EF3822A7290F67DD825C6F93C1982B4A06AEC3515D16C13F7C6EB1A76B1DA7A220703
sha3_384: a613b0cc6e5924ee82c4876dad4950bb6b4d830f7a9729725dacaed4b0b14b196e0ec71f8ed0479b701c1002f4febe91
ep_bytes: 68dc334000e8eeffffff000000000000
timestamp: 2011-09-16 02:10:23

Version Info:

Translation: 0x0409 0x04b0
ProductName: YdOPObyemdVEauj
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ConImofcCxWdzh
OriginalFilename: ConImofcCxWdzh.exe

Win32/AutoRun.VB.AKT also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Sresmon.Gen.1
FireEyeGeneric.mg.ba5aba1dafca1589
SkyhighBehavesLike.Win32.Generic.cm
McAfeeVBObfus.bn
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Sresmon.Gen.1
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Inject.n
VirITWorm.Win32.Generic.AZFG
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AKT
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dfmw
BitDefenderGen:Trojan.Sresmon.Gen.1
NANO-AntivirusTrojan.Win32.VB.cfdsmn
AvastWin32:VB-ABDC [Drp]
SophosMal/SillyFDC-M
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.60
ZillyaWorm.Vobfus.Win32.321359
TrendMicroWORM_VOBFUS.SMHE
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Sresmon.Gen.1 (B)
IkarusWorm.Win32.WBNA
GDataGen:Trojan.Sresmon.Gen.1
JiangminWorm.Vobfus.fwhr
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Vobfus.V.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.AutoRun.AMH@4owee9
ArcabitTrojan.Sresmon.Gen.1
ZoneAlarmWorm.Win32.Vobfus.dfmw
MicrosoftWorm:Win32/Vobfus.gen!N
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.C111088
Acronissuspicious
BitDefenderThetaAI:Packer.C44783DF1F
MAXmalware (ai score=89)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C7 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABDC [Drp]
Cybereasonmalicious.fd42b7
DeepInstinctMALICIOUS

How to remove Win32/AutoRun.VB.AKT?

Win32/AutoRun.VB.AKT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment