Malware

Win32/AutoRun.VB.ARS information

Malware Removal

The Win32/AutoRun.VB.ARS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ARS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.ARS?


File Info:

name: 926721CE55C5EE05735F.mlw
path: /opt/CAPEv2/storage/binaries/5a81f1ac5a12ea73f568b21502c35686110cf4893e3cf43077ed718d92eb5f0b
crc32: C333A311
md5: 926721ce55c5ee05735f69433f80864f
sha1: c3276a52a698a02b21e395b9400037ae7263f63f
sha256: 5a81f1ac5a12ea73f568b21502c35686110cf4893e3cf43077ed718d92eb5f0b
sha512: f49a8603e76101cfa276bfe3cde7d5726939c563eb63cfd80b3a1f4ef48bdc4c658731bd6bd89b427c15a23d9b7338e79c0e7fd90e4793e6a749279b297fdaa4
ssdeep: 6144:TonuUPH3bX2a23NYcJQ8TfxZ85WJ007G9tSBN70Zf:TonuUPH3bX2a23NYcJQ8TfxZ9J0rtSzI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B634E53EB250973EE156C6F56CAE8394406D6D3A25C0A40BFBC23F6976F19B38122753
sha3_384: f6eb2d6350408bec13cc768ee2ab3fd1ff5ff27fa680de3215aa96b959025fc4785cc5c01f5f9c08a82adaf8d1d10195
ep_bytes: 68403d4000e8f0ffffff000000000000
timestamp: 1996-10-24 23:07:49

Version Info:

0: [No Data]

Win32/AutoRun.VB.ARS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.miMq
CynetMalicious (score: 100)
FireEyeGeneric.mg.926721ce55c5ee05
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.df
Cylanceunsafe
ZillyaTrojan.VBKrypt.Win32.790623
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/VBKrypt.45abc03f
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e55c5e
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.SHeur4.PNG
CyrenW32/Vobfus.SL.gen!Eldorado
SymantecW32.Changeup!gen35
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ARS
APEXMalicious
ClamAVWin.Trojan.VB-1613
KasperskyTrojan.Win32.VBKrypt.jctj
BitDefenderGen:Variant.Barys.62377
NANO-AntivirusTrojan.Win32.WBNA.chzvjj
MicroWorld-eScanGen:Variant.Barys.62377
AvastWin32:VB-ABAV [Trj]
TencentTrojan.Win32.Vb.kc
TACHYONTrojan/W32.VB-VBKrypt.233472.AK
SophosMal/Generic-S
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Barys.62377
TrendMicroTROJ_GEN.R002C0CDQ23
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.62377 (B)
IkarusTrojan.Win32.Otran
GDataGen:Variant.Barys.62377
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Barys.DF3A9
ZoneAlarmTrojan.Win32.VBKrypt.jctj
MicrosoftWorm:Win32/Vobfus.gen!T
GoogleDetected
AhnLab-V3Trojan/Win.VBKrypt.R558887
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36196.omY@aWwscCb
ALYacGen:Variant.Barys.62377
MAXmalware (ai score=87)
VBA32BScope.Malware-Cryptor.VBCR.7212
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CDQ23
RisingWorm.Autorun!1.99EA (CLASSIC)
YandexTrojan.GenAsa!QrKV+ICVvgE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.AZGU!tr
AVGWin32:VB-ABAV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.ARS?

Win32/AutoRun.VB.ARS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment