Malware

How to remove “Win32/AutoRun.VB.AMC”?

Malware Removal

The Win32/AutoRun.VB.AMC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AMC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.AMC?


File Info:

name: 301586735B33738C2C23.mlw
path: /opt/CAPEv2/storage/binaries/b6b24d9ac93d50938ea4921ed5939540ae21742f7b37ef53349a93496c02eafc
crc32: D78C4B70
md5: 301586735b33738c2c2361666282bffc
sha1: bf18bccd44dcd2cf2a9a2bdd629d46946751f42c
sha256: b6b24d9ac93d50938ea4921ed5939540ae21742f7b37ef53349a93496c02eafc
sha512: abd22c591cdb08b1c342abcd9be48b587b603e83b0b04065396d8b7329ba209399bdc17de378d58917c2b3d8439280dfb522af640c6db14d640820d76b72a92d
ssdeep: 3072:/a5Xf+DxS95Fbr2IsJ03CwLYwR49hPLd3BzK02Swq4lV34oQZiEJM:C5v+DubrTw03rLlR4PLnh7w1rZWs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140F3942676D0F27DC525CAF4392E83949429ED3765D29C03F6C22F2AB6B1D6BD220317
sha3_384: 4dea2885b33f2154058109a0a784b8afabffdd55133513b1b9b09ae334ad9d2f6670ca4c8c05a6d2f0b9a5b2e5ab66b8
ep_bytes: 6834414000e8f0ffffff000000000000
timestamp: 2011-09-22 06:33:00

Version Info:

Translation: 0x0409 0x04b0
ProductName: SEfDoPaEttHzBL
FileVersion: 1.00
ProductVersion: 1.00
InternalName: uApyiXpvED
OriginalFilename: uApyiXpvED.exe

Win32/AutoRun.VB.AMC also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.luev
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.96973
FireEyeGeneric.mg.301586735b33738c
CAT-QuickHealTrojan.Vobfus.gen
McAfeeVBObfus.bc
Cylanceunsafe
VIPRETrojan.GenericKDZ.96973
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderTrojan.GenericKDZ.96973
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.35b337
ArcabitTrojan.Generic.D17ACD
BitDefenderThetaAI:Packer.A735197920
VirITTrojan.Win32.Zyx.EK
CyrenW32/Vobfus.Z.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AMC
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1563
KasperskyWorm.Win32.Vobfus.dfmo
AlibabaMalware:Win32/km_2ff8.None
NANO-AntivirusTrojan.Win32.Vobfus.cqkyec
ViRobotTrojan.Win32.A.Diple.163840.A
RisingWorm.Vobfus!1.99C7 (CLASSIC)
EmsisoftTrojan.GenericKDZ.96973 (B)
BaiduWin32.Trojan.Inject.n
F-SecureTrojan.TR/Spy.Agent.163849
DrWebTrojan.VbCrypt.60
TrendMicroWORM_DIPLE.SM
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminesuspicious.low.ml.score
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Agent.163849
MAXmalware (ai score=86)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
MicrosoftWorm:Win32/Vobfus.gen!S
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmWorm.Win32.Vobfus.dfmo
GDataWin32.Worm.Vobfus.3ZTMRW
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R13793
ALYacTrojan.GenericKDZ.96973
TACHYONWorm/W32.Vobfus.163840
DeepInstinctMALICIOUS
VBA32BScope.Trojan.VB.Diple.01583
MalwarebytesMalware.AI.3241978625
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_DIPLE.SM
TencentTrojan.Win32.Koobface.p
YandexTrojan.GenAsa!enArhzcyRbM
IkarusWorm.Win32.WBNA
FortinetW32/VB.CNE!worm
AVGWin32:VB-YMU [Trj]
AvastWin32:VB-YMU [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.AMC?

Win32/AutoRun.VB.AMC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment