Malware

What is “Win32/AutoRun.VB.AQP”?

Malware Removal

The Win32/AutoRun.VB.AQP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AQP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AQP?


File Info:

name: 01D2FE8E1C75E44AA6CA.mlw
path: /opt/CAPEv2/storage/binaries/23dcdebfbad29c165cedfcd59ba5f7499a5789bb4cb392b17730c5390c0ea06b
crc32: 41F97D2F
md5: 01d2fe8e1c75e44aa6ca7abc96375706
sha1: 0e55a11f6531d05169f10fefee8a1fd7db629e97
sha256: 23dcdebfbad29c165cedfcd59ba5f7499a5789bb4cb392b17730c5390c0ea06b
sha512: d92ece618e0781eb8a3ba3335fdc06612874277b5d715301df76c68279f1d05c1cd052588c6cca7e3ece4c7b9c9f00ae3117dbc46b73c3645fb201240c9b0ac6
ssdeep: 3072:QnkR+IlgkBfrv67k1jrLXvYNJOLlDrDxUfSGIf9b6L6VlMixFGI5FpqMBDzsUiz5:x+KZrSmrLXeaHDxUadt382FxYIcUutf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10474C51663D0F61AE162CAF0275547949A7EAC3320B4A817F6C52F5973B0E87E632373
sha3_384: deb9cc750da58aa43d09041458eccc072702c89ad9258880baed5b2bbcf7ae216929d37b3874b2159d7186b554b17b16
ep_bytes: 6824484000e8f0ffffff000000000000
timestamp: 2001-11-29 08:48:14

Version Info:

Translation: 0x0409 0x04b0
ProductName: XPjJhjc
FileVersion: 1.00
ProductVersion: 1.00
InternalName: lqROpMEX
OriginalFilename: lqROpMEX.exe

Win32/AutoRun.VB.AQP also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Chinky.7
FireEyeGeneric.mg.01d2fe8e1c75e44a
CAT-QuickHealTrojan.VBCryptVMF.S29961223
SkyhighBehavesLike.Win32.VBObfus.fm
ALYacGen:Variant.Chinky.7
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e1c75e
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.Zyx.HB
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AQP
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.dgex
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.Vobfus.dwtghz
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:VB-AANY [Trj]
TACHYONTrojan/W32.Agent.339968
SophosMal/VBCheMan-J
GoogleDetected
F-SecureTrojan.TR/Diple.eewr
DrWebWorm.Siggen.6785
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Chinky.7 (B)
IkarusWorm.Win32.Vobfus
JiangminTrojan/Diple.deag
VaristW32/Vobfus.Z.gen!Eldorado
AviraTR/Diple.eewr
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4p6cu6
ArcabitTrojan.Chinky.7
ZoneAlarmWorm.Win32.Vobfus.dgex
GDataGen:Variant.Chinky.7
CynetMalicious (score: 100)
Acronissuspicious
McAfeeVBObfus.cm
MAXmalware (ai score=87)
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!2+xcl2cdC98
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaGen:NN.ZevbaF.36802.um0@aO3W5Eci
AVGWin32:VB-AANY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Vobfus.230fea0a

How to remove Win32/AutoRun.VB.AQP?

Win32/AutoRun.VB.AQP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment