Malware

Win32/AutoRun.VB.APV information

Malware Removal

The Win32/AutoRun.VB.APV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.APV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.APV?


File Info:

name: C8EDF85C8110056C0CF5.mlw
path: /opt/CAPEv2/storage/binaries/7a2f76d33d297e7e4ea011165a95cbe1653e813e0cc8fab310cf13c2df430c8c
crc32: C8C093A5
md5: c8edf85c8110056c0cf56e31bef03df0
sha1: 526541fa0b9ebaef9b2888cc4f8d33939e81fed8
sha256: 7a2f76d33d297e7e4ea011165a95cbe1653e813e0cc8fab310cf13c2df430c8c
sha512: 2ae298b515034c6c7111084142d2ad443f1e54050f6d4081c1157a7aa40a61eaf5a194518318ec512ec8b7fd64045e91fcca4d3ab60b378fb9214f8bed222583
ssdeep: 6144:2FaO2IG4GNKnvmb7/D26FfyGarLchgVIxqUrUpUKe5S:QaOlPOKnvmb7/D26SLchgVRP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C24B412BB11B02BE547D9F12A29965A792D2E762B90FC037381AF2571705E3B8F530F
sha3_384: f70cf1e0c2d65f6dda3ca23c49f0186e0f9af4fa7f95d48eb7080d26a1e2911d92d3c7c10d79ecf86a309bb49b726b29
ep_bytes: 68c4364000e8eeffffff000000000000
timestamp: 2011-11-26 07:17:30

Version Info:

0: [No Data]

Win32/AutoRun.VB.APV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.30145
MicroWorld-eScanGen:Variant.VBInject.11
ClamAVWin.Packer.VBCrypt-5731541-0
FireEyeGeneric.mg.c8edf85c8110056c
CAT-QuickHealTrojan.AgentVMF.S25436721
ALYacGen:Variant.VBInject.11
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.3889d52e
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.c81100
BitDefenderThetaGen:NN.ZevbaF.36196.nmW@ayZysfmi
VirITTrojan.Win32.Zyx.GD
CyrenW32/Vobfus.AA.gen!Eldorado
SymantecW32.Changeup!gen15
ESET-NOD32Win32/AutoRun.VB.APV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.abmdx
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.WBNA.crkymm
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:Agent-BAVG [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureTrojan.TR/Otran.aymman
BaiduWin32.Worm.Autorun.l
VIPREGen:Variant.VBInject.11
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dh
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.VBInject.11
AviraTR/Otran.aymman
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBInject.11
ViRobotWorm.Win32.A.WBNA.217088
ZoneAlarmTrojan.Win32.Agent.abmdx
MicrosoftWorm:Win32/Vobfus.gen!O
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R40074
McAfeeVBObfus.by
TACHYONTrojan/W32.VB-Agent.217088.DZ
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaW32/Vobfus.GEP.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!3blfepsHOB4
IkarusTrojan.Win32.Otran
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:Agent-BAVG [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.APV?

Win32/AutoRun.VB.APV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment