Malware

How to remove “Win32/AutoRun.VB.APM”?

Malware Removal

The Win32/AutoRun.VB.APM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.APM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/AutoRun.VB.APM?


File Info:

name: 5094067CCB829FFF7356.mlw
path: /opt/CAPEv2/storage/binaries/a1078975583f2ee4e5ec1da731b9337bd07147b514e2f8899c4180632e122151
crc32: 05506189
md5: 5094067ccb829fff7356a61b5b006a50
sha1: 25052ac386620db7a8ee9935d83bb450c56448d2
sha256: a1078975583f2ee4e5ec1da731b9337bd07147b514e2f8899c4180632e122151
sha512: a64fb6a8cfd1f21eb6daceadb5115e5eb8311ba683f37887390fe6be36a30143444dc3f495d9188a4c0535cbdb44d3a1c1543aa7a9a2279bdbc32af8c1403002
ssdeep: 1536:+VNEfxvOY2zqqYyIow2MJCZ7iqHWWzpatef6O0+DZFT+eP6TfXkcOalSJWYwTLy:UE9l2dYyIow2MJCZ7idewtUY+fT+eP2Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B4730202DD29EA46E0CBA8393F7D8352257FAC621B2D591F3B90336B7E319830E04617
sha3_384: 2b33589cd3ca7af7baf277fe0212c5ed95aeee8c1da1e4bc9f097f99b24783f9017157fc93c8af5937006e9b0ecbcc4f
ep_bytes: b82c6744005064ff3500000000648925
timestamp: 2011-11-16 01:00:22

Version Info:

Comments:
CompanyName: Auto Debug System
FileDescription: Kill Process Module
FileVersion: 1, 1, 1, 10
InternalName: KillProcess
LegalCopyright: Copyright 2003-2007 Auto Debug System
LegalTrademarks:
OriginalFilename: KillProcess.exe
PrivateBuild:
ProductName: KillProcess Module
ProductVersion: 1, 1, 1, 10
SpecialBuild:
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.APM also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Nuev.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38733516
FireEyeGeneric.mg.5094067ccb829fff
McAfeeGenericRXBG-YG!5094067CCB82
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Nuev.vhu
K7AntiVirusP2PWorm ( 00328a831 )
AlibabaWorm:Win32/AutoRun.32a81e01
K7GWP2PWorm ( 00328a831 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.VB.mt
VirITTrojan.Win32.Generic.CGQT
CyrenW32/Buzus.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.VB.APM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Buzus-6998813-0
KasperskyTrojan.Win32.Nuev.vhu
BitDefenderTrojan.GenericKD.38733516
NANO-AntivirusTrojan.Win32.VBKrypt.wpqdj
SUPERAntiSpywareTrojan.Agent/Gen-KProc
AvastWin32:VB-ZTY [Trj]
TencentMalware.Win32.Gencirc.10b4b237
Ad-AwareTrojan.GenericKD.38733516
SophosML/PE-A + Mal/Agent-AFV
ComodoTrojWare.Win32.TrojanDropper.Agent.OFF@4lics1
DrWebTrojan.Packed.22174
ZillyaWorm.AutoRun.Win32.239723
TrendMicroTROJ_AGENT_004794.TOMB
McAfee-GW-EditionGenericRXBG-YG!5094067CCB82
EmsisoftTrojan.GenericKD.38733516 (B)
IkarusTrojan.SuspectCRC
GDataWin32.Trojan.PSE.QLDIC8
JiangminTrojan/Buzus.bcjz
AviraTR/Offend.6991746
Antiy-AVLTrojan/Generic.ASMalwS.23C69
MicrosoftTrojan:Win32/Occamy.CA1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R10911
BitDefenderThetaGen:NN.ZexaF.34212.ei2@a0Ay5Kii
ALYacTrojan.GenericKD.38733516
MAXmalware (ai score=100)
VBA32Trojan.Nuev
MalwarebytesMalware.AI.2129338751
TrendMicro-HouseCallTROJ_AGENT_004794.TOMB
RisingWorm.Autorun!8.50 (CLOUD)
YandexTrojan.Buzus!jZRK4bS/xog
SentinelOneStatic AI – Malicious PE
FortinetW32/AutoRun_VB.APM
AVGWin32:VB-ZTY [Trj]
Cybereasonmalicious.386620
PandaTrj/CI.A
MaxSecureTrojan.Malware.3373567.susgen

How to remove Win32/AutoRun.VB.APM?

Win32/AutoRun.VB.APM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment