Malware

Win32/AutoRun.VB.APL (file analysis)

Malware Removal

The Win32/AutoRun.VB.APL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.APL virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.player1352.com
ns1.player1352.net
ns1.player1352.org

How to determine Win32/AutoRun.VB.APL?


File Info:

crc32: 3E40598B
md5: e95ba0976f994360b00095e9a87772d3
name: E95BA0976F994360B00095E9A87772D3.mlw
sha1: 9ba22698d79cc08170e33c4577d46e9fcba6212f
sha256: 24ce8f829b20bfe742d99ded3ba27afacc950f149f2918dd10e8ac4f62241b50
sha512: 45706117297c316a5833fb8d5191b69c0f5e51b842cb33d3f445197a92c2ba3bbb3e128e69f57606e44454b310c003da7dd3ec5fac63e22b5795b5e5e80ea051
ssdeep: 6144:gAKQc0f7XP+g3AGJpWVzuxmI8nQOsPVKnvmb7/D26Mbj/R8SUHAgOTTMEtBTTlma:i27/XvLWpuUnQOsPVKnvmb7/D26MHUHQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 1.00
InternalName:
FileVersion: 1.00
OriginalFilename:
ProductName:
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.APL also known as:

BkavW32.AIDetect.malware1
K7AntiVirusEmailWorm ( 0054d10f1 )
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.77
CynetMalicious (score: 100)
CylanceUnsafe
SangforWorm.Win32.Vobfus.devi
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.76f994
BaiduWin32.Worm.VB.oz
CyrenW32/Vobfus.Z.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.APL
APEXMalicious
AvastWin32:Regrun-JL [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.devi
BitDefenderGen:Variant.Barys.2644
NANO-AntivirusTrojan.Win32.Jorik.cqkygj
ViRobotWorm.Win32.A.WBNA.294912.U
MicroWorld-eScanGen:Variant.Barys.2644
TencentWorm.Win32.Vobfus.n
Ad-AwareGen:Variant.Barys.2644
SophosML/PE-A + Mal/SillyFDC-T
ComodoWorm.Win32.VB.AUA@4o7zkg
BitDefenderThetaGen:NN.ZevbaF.34266.sq0@a4aQc5di
VIPRETrojan.Win32.Generic!SB.0
TrendMicroWORM_VOBFUS.SM5
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.e95ba0976f994360
EmsisoftGen:Variant.Barys.2644 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm.Vobfus.gtdd
AviraTR/Vobfus.jzka
Antiy-AVLTrojan/Generic.ASBOL.5
MicrosoftWorm:Win32/Vobfus.gen!O
ArcabitTrojan.Barys.DA54
SUPERAntiSpywareTrojan.Agent/Gen-AutoRun
GDataGen:Variant.Barys.2644
TACHYONTrojan/W32.VB-Jorik.294912.E
AhnLab-V3Trojan/Win32.Jorik.R16322
Acronissuspicious
McAfeeVBObfus.by
MAXmalware (ai score=100)
VBA32BScope.Trojan.Diple
MalwarebytesWorm.Obfuscator
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SM5
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!pL2Z1jCqGJ0
IkarusTrojan.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.F
AVGWin32:Regrun-JL [Trj]
Paloaltogeneric.ml

How to remove Win32/AutoRun.VB.APL?

Win32/AutoRun.VB.APL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment