Malware

Win32/AutoRun.VB.AQC removal guide

Malware Removal

The Win32/AutoRun.VB.AQC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AQC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AQC?


File Info:

name: 470A3748BDF9CC4324F4.mlw
path: /opt/CAPEv2/storage/binaries/2f5e73402bf98fae79194ef0e2626d48cf6487eec9b5c5c5ab87dc8e2b488121
crc32: 10DF6C0F
md5: 470a3748bdf9cc4324f4efbfcddf9106
sha1: c55c95451d220223f43d459bea9e0f6b1ac35da1
sha256: 2f5e73402bf98fae79194ef0e2626d48cf6487eec9b5c5c5ab87dc8e2b488121
sha512: 98354203473f81761e01bb32edc1aadf95bbf85446803ce606b7ea2ae9d0dda4c8776fcaa29fac82794d46cca9a1360d1b78b282a2858e3f3275fb628ff92f50
ssdeep: 3072:Rj2DZ3lTBZRtWQSB8feK/fObT/bGi0M16LQGVfBwbMHjRJS3:uZ3lHzWxBPK/fObT/bGi0MUdVfBwbMHu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D04B516BB04B06FE04799F0292D8356792D2D3917A0BC03B7866F1ABA70597B9F071F
sha3_384: 58d99bba68e059c6fce15b9f655869a882eca016aacec38a5e06f19e44381b601cde12e2668c74461212d4d1cc894d87
ep_bytes: 6820364000e8eeffffff000000000000
timestamp: 2011-11-30 21:11:17

Version Info:

0: [No Data]

Win32/AutoRun.VB.AQC also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lsIn
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.97255
FireEyeGeneric.mg.470a3748bdf9cc43
CAT-QuickHealWorm.WbnaVMF.S26739981
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.cf
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.97255
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.ca229e33
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.8bdf9c
BaiduWin32.Worm.Autorun.l
VirITWorm.Win32.Generic.BDTQ
SymantecW32.Changeup!gen15
ESET-NOD32Win32/AutoRun.VB.AQC
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Vobfus-65
KasperskyWorm.Win32.WBNA.bmf
BitDefenderTrojan.GenericKDZ.97255
NANO-AntivirusTrojan.Win32.WBNA.cfdsnr
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
AvastWin32:Regrun-JO [Trj]
TencentWorm.Win32.Vobfus.n
SophosMal/SillyFDC-T
F-SecureWorm.WORM/VBNA.bmham
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMAB
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKDZ.97255 (B)
IkarusWorm.Win32.WBNA
GoogleDetected
AviraWORM/VBNA.bmham
VaristW32/Vobfus.AA.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D17BE7
ZoneAlarmWorm.Win32.WBNA.bmf
GDataTrojan.GenericKDZ.97255
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R18479
Acronissuspicious
VBA32BScope.Trojan.Diple
ALYacTrojan.GenericKDZ.97255
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VBCode!1.6588 (CLASSIC)
YandexTrojan.GenAsa!ltEwzYaDX14
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.ADV!tr
BitDefenderThetaGen:NN.ZevbaF.36802.lmW@aa7l8ahi
AVGWin32:Regrun-JO [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.a5630228

How to remove Win32/AutoRun.VB.AQC?

Win32/AutoRun.VB.AQC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment