Malware

Should I remove “Win32/AutoRun.VB.APG”?

Malware Removal

The Win32/AutoRun.VB.APG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.APG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.APG?


File Info:

name: A6120ACC99EA74FA0E18.mlw
path: /opt/CAPEv2/storage/binaries/3844cebc0264ff36bcd6d377c5750f487fad4c12ca993964cc22a7c3dc0ef7f7
crc32: 704A35F1
md5: a6120acc99ea74fa0e1803c014dcac7b
sha1: 488f29d07a2722306b32fcb0de8dd76f1f1ea68e
sha256: 3844cebc0264ff36bcd6d377c5750f487fad4c12ca993964cc22a7c3dc0ef7f7
sha512: 3a6fd29f8365a742bf228020cf7b894d714c89a04d5f7f2348121f5fd28f97c4c5fac287f32cdc7c76c9ad999a9603ef254767bc88303fc5eb0d79a639414455
ssdeep: 6144:lZqO1FrSU0bIaX/m7bfTWaJPGeyb7qh7wNAZBbM3f1mD:lZqO/SU0bIaX/m7bfTWaV1wWZBbM3f1Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B244C616BA11F02ED197C5F66939822A35292D761691BC0B72C17F5E7BB0283B8F170F
sha3_384: 23324e2d7be82e4c2cd3c265831a685f2860f01a56849782108ff6e03131083385cbce1dbd2ebb224c15e7c6e4379ff7
ep_bytes: 6808394000e8f0ffffff000000000000
timestamp: 1995-07-12 20:29:51

Version Info:

0: [No Data]

Win32/AutoRun.VB.APG also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.459850
FireEyeGeneric.mg.a6120acc99ea74fa
CAT-QuickHealW32.Virut.G
SkyhighBehavesLike.Win32.VBObfus.dt
McAfeeVBObfus.dq
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1520596
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2faa.None
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36802.qqZ@aiKBFRf
VirITTrojan.Win32.Generic.CCVG
SymantecW32.Changeup!gen15
ESET-NOD32Win32/AutoRun.VB.APG
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.eeoq
BitDefenderGen:Variant.Zusy.459850
NANO-AntivirusTrojan.Win32.WBNA.cihugk
AvastWin32:Vitro [Inf]
TencentWorm.Win32.Vobfus.ks
EmsisoftGen:Variant.Zusy.459850 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.150
VIPREGen:Variant.Zusy.459850
TrendMicroCryp_VBNA-8
Trapminemalicious.high.ml.score
SophosMal/VBCheMan-J
IkarusWorm.Win32.AutoRun
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Vobfus.AA.gen!Eldorado
Antiy-AVLVirus/Win64.Expiro.rsrc
KingsoftWin32.Worm.Vobfus.eeoq
MicrosoftWorm:Win32/Vobfus.DP
ArcabitTrojan.Zusy.D7044A
ZoneAlarmWorm.Win32.Vobfus.eeoq
GDataGen:Variant.Zusy.459850
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R185811
Acronissuspicious
VBA32BScope.Trojan.Diple
ALYacGen:Variant.Zusy.459850
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.Vobfus!8.10E (TFE:1:xI9XenCGlvT)
YandexTrojan.GenAsa!SVPuqe1JkvE
MAXmalware (ai score=81)
FortinetW32/VB.ADV!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.DP

How to remove Win32/AutoRun.VB.APG?

Win32/AutoRun.VB.APG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment