Malware

Win32/AutoRun.VB.ANT removal guide

Malware Removal

The Win32/AutoRun.VB.ANT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ANT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ANT?


File Info:

name: 5E605783441860986A3F.mlw
path: /opt/CAPEv2/storage/binaries/b298d56dba0b060fbb14883dc3646f7f8c69519556811b60c06b54ce3c692789
crc32: E4637AFA
md5: 5e605783441860986a3fb4d59241e20d
sha1: 0ecb900774d33ac045d4eb5ca623bffdc6bbc76b
sha256: b298d56dba0b060fbb14883dc3646f7f8c69519556811b60c06b54ce3c692789
sha512: e10f3647ca77fb691164e3b72a72464e7eb05fa90d2f1d8c6fa16f6c3c140be0d7395e6ef8902950d43bd75c22f4b698e0b0bd830279b5474f7a916bcfe8e870
ssdeep: 3072:qzpUmUP8b8RuBnI16UCceGyYyKnvmb7/D26VNr79JEx/G/OOIVLM/tAGjiBuAZde:8NUkwuBnI16ZoGKnvmb7/D26P/9JEx/E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF04B716BA05A06FE552D9F02A3C978A38392D371790BC57F7856F54A6B00A7B4F032F
sha3_384: dce309d8418de0fd2ca3b1d3aa1617d6668dd6deef15080be9698063d353da67b053ebb63e46e201bf8e7f8bd6058921
ep_bytes: 6898384000e8eeffffff000000000000
timestamp: 2011-10-13 14:38:10

Version Info:

gh: ertet

Win32/AutoRun.VB.ANT also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lw12
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.23
ClamAVWin.Trojan.Diple-17
FireEyeGeneric.mg.5e60578344186098
CAT-QuickHealWorm.VobfusVMF.S20100107
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.l
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.1e53975e
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.774d33
BitDefenderThetaAI:Packer.DA0EAA1720
VirITTrojan.Win32.Generic.ACVO
SymantecW32.Changeup!gen15
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.ANT
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.devc
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.Diple.crgjdi
SUPERAntiSpywareTrojan.Agent/Gen-Autorun[VB]
AvastWin32:VB-ZBQ [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.Vobfus.180224.E
EmsisoftGen:Variant.VBKrypt.23 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Spy.Agent.176129
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.VBKrypt.23
TrendMicroWORM_VOBFUS.SMAC
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-T
IkarusWorm.Win32.Vobfus
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Spy.Agent.176129
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.gen!O
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBKrypt.23
ZoneAlarmWorm.Win32.Vobfus.devc
GDataGen:Variant.VBKrypt.23
VaristW32/Vobfus.AA.gen!Eldorado
AhnLab-V3Trojan/Win32.Diple.R14477
Acronissuspicious
VBA32BScope.Worm.Vobfus
ALYacGen:Variant.VBKrypt.23
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAC
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!SmglMj6QaaY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.ZMH2!tr
AVGWin32:VB-ZBQ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.ANT?

Win32/AutoRun.VB.ANT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment