Malware

Win32/AutoRun.VB.AQW information

Malware Removal

The Win32/AutoRun.VB.AQW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AQW virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.musiczipz.com
ns1.musicmixa.net
ns1.musicmixa.org
ns1.musicmixb.co
ns1.musicmixc.com

How to determine Win32/AutoRun.VB.AQW?


File Info:

crc32: 2ABB136E
md5: 5dbd1bfaa9b210a70feddfbde8e560fd
name: 5DBD1BFAA9B210A70FEDDFBDE8E560FD.mlw
sha1: 2840509214c1cb143fd40bdbee08f8cd6fb2c84f
sha256: 229b4e1dc83c95c44436018c2abaa09707d73efff38dceed4580177db9551b80
sha512: 109c89cbf9eaf9779dd8fa95079793bdda51d4789d542e7688bcf607eb6acf99ac86be7afc18ac76c070c0a83873416c9c984ab19dba3c97b37a703f8a034268
ssdeep: 1536:jxVVLz2cGCyFLAx4cd9Lv2PElgWEVNoN274B/K51ptaHElfTczp6Far2/AgAISF:9LyH9Up+ZVNoN2N04A1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/AutoRun.VB.AQW also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.5dbd1bfaa9b210a7
ALYacGen:Variant.VBInject.11
CylanceUnsafe
VIPREWorm.Win32.Vobfus.fi (v)
SangforMalware
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.VBInject.11
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.aa9b21
BitDefenderThetaGen:NN.ZevbaF.34804.nmW@amC4psd
CyrenW32/Vobfus.AV.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AQW
BaiduWin32.Worm.VB.lf
APEXMalicious
AvastWin32:VB-ADDH [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.ekue
NANO-AntivirusTrojan.Win32.Jorik.eijubo
Ad-AwareGen:Variant.VBInject.11
SophosML/PE-A + W32/Vobfus-AY
F-SecureTrojan.TR/Jorik.ektcya
DrWebWin32.HLLW.Autoruner1.16646
TrendMicroWORM_VOBFUS.SMK7
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dt
EmsisoftGen:Variant.VBInject.11 (B)
IkarusWorm.Win32.Vobfus
JiangminTrojan/Vobfus.ngv
eGambitUnsafe.AI_Score_100%
AviraTR/Jorik.ektcya
MAXmalware (ai score=88)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.FI
ArcabitTrojan.VBInject.11
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AhnLab-V3Trojan/Win32.Jorik.C644758
ZoneAlarmTrojan.Win32.Jorik.Vobfus.ekue
GDataGen:Variant.VBInject.11
CynetMalicious (score: 100)
TotalDefenseWin32/Vobfus.AID
Acronissuspicious
McAfeeVBObfus.dv
TACHYONTrojan/W32.VB-Jorik.217088.G
VBA32TScope.Trojan.VB
MalwarebytesVobfus.Worm.Evasion.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMK7
RisingWorm.Vobfus!8.10E (TFE:3:pv4i9dZscLJ)
YandexTrojan.GenAsa!84xBAroWknk
SentinelOneStatic AI – Malicious PE – Worm
MaxSecureWorm.VBNA.b
FortinetW32/Jorik.EGLG!tr
AVGWin32:VB-ADDH [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM03.0.061F.Trojan.Win32.Jorik

How to remove Win32/AutoRun.VB.AQW?

Win32/AutoRun.VB.AQW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment