Malware

Win32/AutoRun.VB.ANN removal

Malware Removal

The Win32/AutoRun.VB.ANN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ANN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ANN?


File Info:

name: B304FB865A37014EF138.mlw
path: /opt/CAPEv2/storage/binaries/47e5102f1991ddf1a1a898ed5ce56b5963a46c706a646d60402acab6688320ee
crc32: 25F82C2B
md5: b304fb865a37014ef138faa25ebf70b6
sha1: c10a3196e5cb830a9a2551a18a66777d2a13dd15
sha256: 47e5102f1991ddf1a1a898ed5ce56b5963a46c706a646d60402acab6688320ee
sha512: 8717ba6ecee08ac9a7ced78b439a6644d1bfebac5bff2f0c1627430f5cb37cc129c53ee7650a19bc9f38d2ff7e22f58d31090d301b245d42d927ff8fe3747d9f
ssdeep: 3072:QC1IrAb+gj2HsfyKnvmb7/D26zjlBvWlzPpsPfIQ8sqLELTS55pMzcUK1eUyGez:tb+1Knvmb7/D26zjlBvWhPpsPfIQ8sqI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16804A6166B02A06FE507D8F0692C979A38281D3727C0BC577781AF59B6B0997B4F036F
sha3_384: 8d6ecf57d07a6fb5418900ded6215d3585f68d31e784eef4a0a1b371f4d758c790b30807eddea8db860d271c28e5ad47
ep_bytes: 68b0384000e8f0ffffff000000000000
timestamp: 2011-10-10 05:57:59

Version Info:

d: g

Win32/AutoRun.VB.ANN also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.23
FireEyeGeneric.mg.b304fb865a37014e
CAT-QuickHealWorm.VobfusVMF.S28094788
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.l
MalwarebytesGeneric.Worm.AutoRun.DDS
ZillyaWorm.Vobfus.Win32.1525247
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Vobfus.9ebc5085
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
ArcabitTrojan.VBKrypt.23
BitDefenderThetaAI:Packer.446F261620
VirITTrojan.Win32.Generic.YYQ
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.ANN
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMHF
AvastWin32:VB-YZH [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dewm
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.Diple.cqkxqq
SUPERAntiSpywareTrojan.Agent/Gen-Vban[Local]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.VBKrypt.23 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Diple.cdzya
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.VBKrypt.23
TrendMicroWORM_VOBFUS.SMHF
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-T
MAXmalware (ai score=81)
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Diple.cdzya
VaristW32/Vobfus.Z.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.Vobfus.dewm
XcitiumTrojWare.Win32.Diple.EMIB@4pez3w
MicrosoftWorm:Win32/Vobfus.gen!O
ZoneAlarmWorm.Win32.Vobfus.dewm
GDataGen:Variant.VBKrypt.23
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R19413
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Variant.VBKrypt.23
TACHYONTrojan/W32.Agent.180224.B
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DC (CLASSIC)
IkarusTrojan.Win32.Diple
MaxSecureTrojan.Diple.cdzy
FortinetW32/VB.ADV!tr
AVGWin32:VB-YZH [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.75592579

How to remove Win32/AutoRun.VB.ANN?

Win32/AutoRun.VB.ANN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment