Malware

What is “Win32/AutoRun.VB.APK”?

Malware Removal

The Win32/AutoRun.VB.APK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.APK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.APK?


File Info:

name: 68B48CFA75574B7674D0.mlw
path: /opt/CAPEv2/storage/binaries/da3e5016cbe365d98b2059c451dc8860ef7913aef120b01e3de5790f9aa39653
crc32: D5663B68
md5: 68b48cfa75574b7674d0ea976db139ef
sha1: 525c766aef894cad2365861950f7f0eb9f2f71ac
sha256: da3e5016cbe365d98b2059c451dc8860ef7913aef120b01e3de5790f9aa39653
sha512: 12cef2cabc630179f39385e73ebe85e40229b8abe87c534e57c9a5a12cdb7bfc0d69dbb46c189b5223bee39464f765f32da6f5e26c16e268182499900ddf7c29
ssdeep: 6144:uOc0f7XP+g3AGJpWVzufVhYrgns+XuCKnvmb7/D263VAPL8R8FUjcWMHu9tmuE7L:s27/XvLWpufnogns+XuCKnvmb7/D263s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122542813BB10712FE65284F02A6C86A7B9292D7527907C077381FF2965B05ABF9B035F
sha3_384: b8743666ea92810da0ae598a072d68832bda02a7eb7060ddaf76750265f4dd5888e33052d1d1d31c3eb16feadbb31328
ep_bytes: 6854394000e8eeffffff000000000000
timestamp: 2011-11-17 20:09:15

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.APK also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lrSX
AVGWin32:AutoRun-CKG [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.77
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.68b48cfa75574b76
CAT-QuickHealWorm.VobfusVMF.S19738946
SkyhighBehavesLike.Win32.VBObfus.dh
ALYacGen:Variant.VBInject.11
Cylanceunsafe
ZillyaWorm.WBNAGen.Win32.20
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.f580270c
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36804.sm0@aOCghmdi
VirITTrojan.Win32.Zyx.FX
Paloaltogeneric.ml
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.APK
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:AutoRun-CKG [Trj]
ClamAVWin.Worm.Vobfus-11
KasperskyWorm.Win32.Vobfus.dgnj
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.VB.hnzswb
SUPERAntiSpywareTrojan.Agent/Gen-Vban
TencentTrojan.Win32.FakeFolder.piz
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureTrojan.TR/Vobfus.jzka
BaiduWin32.Worm.Autorun.l
VIPREGen:Variant.VBInject.11
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-GI
IkarusTrojan.Vobfus
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraTR/Vobfus.jzka
MAXmalware (ai score=100)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBInject.11
ViRobotTrojan.Win32.A.Diple.294912.G
ZoneAlarmWorm.Win32.Vobfus.dgnj
GDataGen:Variant.VBInject.11
VaristW32/Vobfus.Z.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R16322
Acronissuspicious
McAfeeVBObfus.by
TACHYONWorm/W32.Vobfus.294912.B
VBA32BScope.Trojan.Diple
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Autorun.BJ
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!pL2Z1jCqGJ0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.004716f9

How to remove Win32/AutoRun.VB.APK?

Win32/AutoRun.VB.APK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment