Malware

Win32/AutoRun.VB.ARA (file analysis)

Malware Removal

The Win32/AutoRun.VB.ARA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ARA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ARA?


File Info:

name: 7CB7E7C23B30009A8518.mlw
path: /opt/CAPEv2/storage/binaries/215912afacd4a729d4d9c6feaa8113f65283153b41a9fb654efc82a836193942
crc32: 98C2527A
md5: 7cb7e7c23b30009a8518d579469d9ff6
sha1: 042e9d15fc1e9edf4e683d1082fd2cb1b6e8373f
sha256: 215912afacd4a729d4d9c6feaa8113f65283153b41a9fb654efc82a836193942
sha512: cad537f59e338060bc7fc2ec8634ccbdda2da656c14164134b3613bf3dd53ca5ee73cc79c3f1905cbbfc1057388b16cd2466fed91eaa2d68cc31c71187551a5d
ssdeep: 3072:miu7ehhNrWlAIJqPYNbihKovbAM4VkRvjCKuz3EwBT3edZlSL6aOuTOunpE7bVGQ:m5uhNrWlAIJqPYNbihRzrNvjITEeedZA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15904E52D72909B3FE4A9E6F5292E839840196E3918D4E853F7C16B1D71F0AE3D13235B
sha3_384: a4cdbb794ded5a786345ec1e5490b6e80290dc1a3add60ad6c9dd7bfed5b0e8b99ce117a34a1e840bd4864baf1b628bf
ep_bytes: 68943a4000e8f0ffffff000000000000
timestamp: 2012-01-26 06:44:09

Version Info:

Translation: 0x0409 0x04b0
ProductName: UxjQEt
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Dxocajwvof
OriginalFilename: Dxocajwvof.exe

Win32/AutoRun.VB.ARA also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-AAWR [Trj]
MicroWorld-eScanGen:Variant.Chinky.7
CAT-QuickHealWorm.VobfusVMF.S19740322
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.cu
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.23b300
BaiduWin32.Worm.Pronny.d
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ARA
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:VB-AAWR [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dfpq
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.VBKrypt.cihuha
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
TencentWorm.Win32.Vobfus.n
SophosMal/VBCheMan-B
F-SecureTrojan.TR/Otran.ammnb
DrWebWorm.Siggen.7007
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7cb7e7c23b30009a
EmsisoftGen:Variant.Chinky.7 (B)
IkarusWorm.Win32.Vobfus
VaristW32/Vobfus.AI.gen!Eldorado
AviraTR/Otran.ammnb
MAXmalware (ai score=87)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Chinky.7
ViRobotTrojan.Win32.A.VBKrypt.184320.CE
ZoneAlarmWorm.Win32.Vobfus.dfpq
GDataGen:Variant.Chinky.7
GoogleDetected
AhnLab-V3Trojan/Win32.VB.R19758
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.lm0@aSW7oDfi
ALYacGen:Variant.Chinky.7
TACHYONWorm/W32.Vobfus.184320
VBA32BScope.Trojan.VBCR.2512
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!p5p9FWs+0AI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.AZGU!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan:Win/Vobfus.54ccc27c

How to remove Win32/AutoRun.VB.ARA?

Win32/AutoRun.VB.ARA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment