Malware

Should I remove “Win32/AutoRun.VB.APT”?

Malware Removal

The Win32/AutoRun.VB.APT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.APT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.APT?


File Info:

name: 94CD969C969F2381E629.mlw
path: /opt/CAPEv2/storage/binaries/ed08f866e8b16ca4b9ff8552f9f19161e4ac3ec5a2ea6c6fc2aff98709c1d90c
crc32: 6BB36E93
md5: 94cd969c969f2381e629ef632672b27c
sha1: 031077a7b1e0481b6dcf40885fff7048d135b831
sha256: ed08f866e8b16ca4b9ff8552f9f19161e4ac3ec5a2ea6c6fc2aff98709c1d90c
sha512: accc2e0e230db22a050635a70de38c026f9b1a525b78d520932c7d37bf64afe5f36e004e522f10640a2395f791d8d723c2efe128257c163b50cd2e71ccc6d651
ssdeep: 6144:K9X88SaX/m7bfTWarM1jP1pQcxMteDUy29Bn79Nu/NJ/V66xL4pce5Se:r8SaX/m7bfTWa0QcxMteDUykB7zu/nVA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13564A50BF724E01FD406C5F1996F826A7D282D761B52AD4373807F1AA6B11A77AB070F
sha3_384: ed0d07cbe72594bde21d804832dd473090c00f1a855cabbeec644ec6ad0a142317ed3e6c9a7f29f58481424b07d02fb2
ep_bytes: 6884414000e8eeffffff000000000000
timestamp: 2011-11-25 05:53:31

Version Info:

FileVersion: 1.00
ProductVersion: 1.00

Win32/AutoRun.VB.APT also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.94cd969c969f2381
CAT-QuickHealWorm.VobfusoVMF.S19741013
SkyhighBehavesLike.Win32.VBObfus.fm
McAfeeVBObfus.ca
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.VBInject.11
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Autorun.l
VirITWorm.Win32.Generic.BDLL
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.APT
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.kao
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.VB.cihugi
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:Regrun-JN [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.VB-Jorik.327680.D
EmsisoftGen:Variant.VBInject.11 (B)
GoogleDetected
F-SecureTrojan.TR/VB.Inject.115585
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SM7
Trapminesuspicious.low.ml.score
SophosMal/SillyFDC-T
IkarusWorm.Win32.Vobfus
WebrootW32.Trojan.Diple.Gen
VaristW32/Vobfus.AA.gen!Eldorado
AviraTR/VB.Inject.115585
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus.gen!O
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBInject.11
ViRobotWorm.Win32.A.WBNA.327680.H
ZoneAlarmTrojan.Win32.Jorik.Vobfus.kao
GDataGen:Variant.VBInject.11
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R18663
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.um0@aK3Fgnii
ALYacGen:Variant.VBInject.11
MAXmalware (ai score=87)
VBA32BScope.Worm.Vobfus
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM7
RisingWorm.VobfusEx!1.99DB (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.CM!tr
AVGWin32:Regrun-JN [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.7297bce0

How to remove Win32/AutoRun.VB.APT?

Win32/AutoRun.VB.APT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment