Malware

Win32/AutoRun.VB.AOK (file analysis)

Malware Removal

The Win32/AutoRun.VB.AOK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AOK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AOK?


File Info:

name: A89949C796B14F8022C0.mlw
path: /opt/CAPEv2/storage/binaries/36c36d2d1d84ce321151aae2559576225d5185bacd97a1f81e54fac8be6e517f
crc32: ED1F2BD3
md5: a89949c796b14f8022c061ae0e0927ab
sha1: 74d90df7f9a597d8b8d11303136e71a6fa2fc153
sha256: 36c36d2d1d84ce321151aae2559576225d5185bacd97a1f81e54fac8be6e517f
sha512: 3a04ac38bb6abb4c2b534544000209d054e3cdaf376b04593e05e3ca2e4e1a176108179d40fe52b17cb94b1eac7a3fd4c89a0d64df060fd413e0591e0d449791
ssdeep: 6144:kkSD1y0FXrKnvmb7/D26OJYPsMiqDJlJNwHG6s20EBb4jHX3QA/hwNGhWhThPvMd:kdD1y0F7Knvmb7/D265DJlJNwHG6JTbO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E545317FB00A11AF56248F03A2DAB965D292D373650BC07BB835B1865B16DBB8F071F
sha3_384: 6fd2ef0ec8d3e5f858917362e56225cbd64c93934980b31660c526d0e96b005f1cbff2812098c84fdd0085df15939baa
ep_bytes: 68783b4000e8eeffffff000000000000
timestamp: 2011-10-27 18:18:51

Version Info:

0: [No Data]

Win32/AutoRun.VB.AOK also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.23
CAT-QuickHealWorm.VobfusVMF.S28965266
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.bs
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.796b14
BitDefenderThetaAI:Packer.CA46F90C20
VirITTrojan.Win32.Zyx.FJ
SymantecW32.Changeup.C
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AOK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dfrp
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.WBNA.cqkxpd
AvastWin32:Evo-gen [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.Vobfus.303104
EmsisoftGen:Variant.VBKrypt.23 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Spy.Agent.303121
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.VBKrypt.23
TrendMicroWORM_VOBFUS.SMAC
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a89949c796b14f80
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.Z.gen!Eldorado
AviraTR/Spy.Agent.303121
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus.DM
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBKrypt.23
ZoneAlarmWorm.Win32.Vobfus.dfrp
GDataGen:Variant.VBKrypt.23
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R15226
Acronissuspicious
VBA32BScope.Trojan.Menti
ALYacGen:Variant.VBKrypt.23
MAXmalware (ai score=89)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAC
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!VQxTR22XDp8
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Menti.ioif
FortinetW32/VB.ADV!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[spy]:Win/Vobfus.6b765a4e

How to remove Win32/AutoRun.VB.AOK?

Win32/AutoRun.VB.AOK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment