Malware

Win32/AutoRun.VB.AMZ removal instruction

Malware Removal

The Win32/AutoRun.VB.AMZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AMZ virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Creates an autorun.inf file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/AutoRun.VB.AMZ?


File Info:

crc32: D1AA36FB
md5: 8d4e5405ae19dbb8974372268a8603f4
name: 8D4E5405AE19DBB8974372268A8603F4.mlw
sha1: a2855550498ab126ab20349a72dbc7361a9831e8
sha256: d5847ee90f94d514ea3b222427a1f202ba8a59c1a4093b897b4b53ad0b0bd8b4
sha512: f48fe5ed648bc668ac8fa5a620a1f2a199b9593d50cf7c86f7b2e4a7d40a2308593bc39210552c38bfec2f3fe7b4888261611422b83b5a624f3c5531fc742724
ssdeep: 6144:U2oZqAYTSE0CzjeNH0LCZhwcU8oa7bN4iAdyk2xoexGET1vWy2U:UX0eZhJ9H7bSbMkWoexGO1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyrix167ht: MicrOsoft Wx16frd Documx2065nt x220 0 x2020 0 ` 0 xa0 0 x2020
InternalName: Ms Word
FileVersion: 1.00
CompanyName: Microsoft xa9 Corporation x420 x220 x120 x120 x220 x221
Legax406cTrademarks: Micbosoft Word Document x1020
Comments: Microsoft Word Document
ProductName: Microsoft Word Document
ProductVersion: 1.00
FileDesx163ription: Microsoft x157orx864 Document x220 " x120 x4020 ! x220 x420 x1020 ( x420 x1020 x820
OriginalFilename: Ms Word.exe

Win32/AutoRun.VB.AMZ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.Gu1@sfuiaYfif
FireEyeGeneric.mg.8d4e5405ae19dbb8
CAT-QuickHealTrojan.Comame.AZ3
ALYacGen:Trojan.Heur.Gu1@sfuiaYfif
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Swisyn.kZb9
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Trojan.Heur.Gu1@sfuiaYfif
K7GWP2PWorm ( 004d2e201 )
K7AntiVirusP2PWorm ( 004d2e201 )
BitDefenderThetaAI:Packer.BF4B0FB11D
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.VB.AMZ
BaiduWin32.Worm.AutoRun.bi
TrendMicro-HouseCallTROJ_SWISYN_000006c.TOMA
AvastWin32:Patched-AFR [Trj]
ClamAVWin.Dropper.Swisyn-6832473-0
KasperskyTrojan.Win32.Swisyn.bvpz
AlibabaTrojan:Win32/udisk.ali1000021
NANO-AntivirusTrojan.Win32.Swisyn.wghai
RisingWorm.Autorun!1.99ED (CLOUD)
Ad-AwareGen:Trojan.Heur.Gu1@sfuiaYfif
SophosMal/Generic-S
ComodoWorm.Win32.VB.amz@4s3j97
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.DownLoader5.17157
ZillyaTrojan.Swisyn.Win32.29672
TrendMicroTROJ_SWISYN_000006c.TOMA
McAfee-GW-EditionBehavesLike.Win32.Generic.ht
EmsisoftGen:Trojan.Heur.Gu1@sfuiaYfif (B)
IkarusTrojan.Win32.Swisyn
JiangminWin32/Virut.bv
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Swisyn.bvpz
MicrosoftTrojan:Win32/Dorv.A
ArcabitTrojan.Heur.ED12130
AhnLab-V3Packed/Win32.Krap.C70378
ZoneAlarmTrojan.Win32.Swisyn.bvpz
GDataGen:Trojan.Heur.Gu1@sfuiaYfif
CynetMalicious (score: 100)
TotalDefenseWin32/VB.LERZPSD
Acronissuspicious
McAfeeW32/Worm-FDN!8D4E5405AE19
VBA32TScope.Trojan.VB
MalwarebytesNimnul.Virus.FileInfector.DDS
PandaGeneric Malware
APEXMalicious
TencentVirus.Win32.Virut.ua
YandexTrojan.GenAsa!XgCKClU0Fi8
SentinelOneStatic AI – Malicious PE – Worm
MaxSecureVirus.Virut.CE
FortinetW32/VB.AMZ!tr
AVGWin32:Patched-AFR [Trj]
Cybereasonmalicious.5ae19d
Paloaltogeneric.ml
Qihoo-360Malware.Radar01.Gen

How to remove Win32/AutoRun.VB.AMZ?

Win32/AutoRun.VB.AMZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment