Malware

What is “Win32/AutoRun.VB.AMP”?

Malware Removal

The Win32/AutoRun.VB.AMP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AMP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AMP?


File Info:

name: C933C45B5F5E7057444F.mlw
path: /opt/CAPEv2/storage/binaries/d1a3681582ad973d51c989f740e4a99cbe9a0fad6729780e67694ac222ef7f8f
crc32: CE3B3001
md5: c933c45b5f5e7057444f533d712b71d2
sha1: 9ab7f010d7a337465532a3a22e4a0db5c304d0b6
sha256: d1a3681582ad973d51c989f740e4a99cbe9a0fad6729780e67694ac222ef7f8f
sha512: b8380995f1533016a254ddc4c73324e0227351b436fce7d4c3c662d53d59811cab0cb4073bf801d46beed334fef8697685f7bb42969fe66b7d5419079a0a6d92
ssdeep: 196608:1IAOpCA4N+Jh55WGQCBni/kzdLJTg4JPo+odtHvpYj2jZX22bB6:aQA4NuhuZN/GxtP0tPp4C6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA863355E8368BC3D6412EB85A47F3A22A658C44FFD088C4BF78B48C9F75740839796E
sha3_384: c75ebbc40451e6db3bebf5f66c8fb4e38275ce0f6bcbfbc0e677e4b8088d36da6248d91e2565c6e4d6d8ec8f7e292f5e
ep_bytes: 60be006040008dbe00b0ffff57eb0b90
timestamp: 2008-06-01 21:58:02

Version Info:

0: [No Data]

Win32/AutoRun.VB.AMP also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.VB.Autorun.AF
CAT-QuickHealTrojan.AgentMF.S26669773
SkyhighW32/Autorun.worm.ie
McAfeeW32/Autorun.worm.ie
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.VB.Win32.1814985
K7AntiVirusEmailWorm ( 005327171 )
K7GWEmailWorm ( 005327171 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.VB.Autorun.AF
BaiduWin32.Worm.VB.g
SymantecW32.Bluven
ESET-NOD32a variant of Win32/AutoRun.VB.AMP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Score-6830630-0
KasperskyTrojan.Win32.VB.enm
BitDefenderTrojan.VB.Autorun.AF
NANO-AntivirusTrojan.Win32.VB.cqkxjh
AvastWin32:Evo-gen [Trj]
TencentWorm.Win32.Autorun.aar
EmsisoftTrojan.VB.Autorun.AF (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen3.63843
VIPRETrojan.VB.Autorun.AF
FireEyeGeneric.mg.c933c45b5f5e7057
SophosTroj/VBDrpB-Gen
SentinelOneStatic AI – Malicious PE
JiangminTrojan/VB.ckgb
VaristW32/FakeDoc.CE.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VB
XcitiumWorm.Win32.Autorun.h0@143j1r
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.VB.113692[UPX]
ZoneAlarmTrojan.Win32.VB.enm
GDataTrojan.VB.Autorun.AF
GoogleDetected
AhnLab-V3Trojan/Win.VB.R644264
Acronissuspicious
BitDefenderThetaAI:Packer.B76662921D
ALYacTrojan.VB.Autorun.AF
MAXmalware (ai score=81)
VBA32Trojan.VB
PandaGeneric Malware
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
YandexTrojan.GenAsa!WzfYyst7b2g
IkarusWorm.Win32.AutoRun
FortinetW32/VB.ENM!tr
DeepInstinctMALICIOUS

How to remove Win32/AutoRun.VB.AMP?

Win32/AutoRun.VB.AMP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment