Malware

Should I remove “Win32/AutoRun.VB.ASX”?

Malware Removal

The Win32/AutoRun.VB.ASX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ASX virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.spansearcher.net
redirector.gvt1.com
r3—sn-4g5e6nzz.gvt1.com

How to determine Win32/AutoRun.VB.ASX?


File Info:

crc32: D51DD7CA
md5: 59651c29fefa9ab1a1193ecb805397bf
name: 59651C29FEFA9AB1A1193ECB805397BF.mlw
sha1: 08b26402da207c679ba024a8aef8b6841ae27931
sha256: 96daf64ee28a112a6c3574e933954d50d0d3126d7f45970483136d62629b4ff4
sha512: c7b305dec36fe21dc79c19e2e57f450cd560975d9adfa54572f43f2cfc11c381abbc965fb4f190d4de8a1dadfa2b4b103841acddcf4c9c9a572c229904e16073
ssdeep: 3072:fmkiGtXOTPI/YXYqqd8MoNrozX+h2RAGCD6fWtQ/Tm:fmY3/qqdGrhAey6Q/K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: sVohld
FileVersion: 1.00
OriginalFilename: sVohld.exe
ProductName: RMvNmn

Win32/AutoRun.VB.ASX also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Chinky.7
FireEyeGeneric.mg.59651c29fefa9ab1
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Chinky.7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Chinky.7
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.9fefa9
BaiduWin32.Trojan.Inject.n
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
APEXMalicious
AvastWin32:Regrun-MQ [Trj]
ClamAVWin.Packer.VBCrypt-5731517-0
KasperskyWorm.Win32.Vobfus.dbxo
NANO-AntivirusTrojan.Win32.VB.chvyyf
ViRobotWorm.Win32.A.WBNA.233472.CH
RisingTrojan.Win32.Generic.12BB7942 (C64:YzY0Ov0JEkum0aCP)
Ad-AwareGen:Variant.Chinky.7
TACHYONTrojan/W32.Jorik.233472
SophosML/PE-A + W32/SillyFDC-HQ
ComodoTrojWare.Win32.VB.AVA@4paxk7
F-SecureTrojan.TR/Kazy.62009
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
EmsisoftGen:Variant.Chinky.7 (B)
SentinelOneStatic AI – Malicious PE – Worm
GDataGen:Variant.Chinky.7
JiangminTrojan/Vbobf.b
AviraTR/Kazy.62009
eGambitUnsafe.AI_Score_99%
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Chinky.7
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmWorm.Win32.Vobfus.dbxo
MicrosoftWorm:Win32/Vobfus.gen!R
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R48305
Acronissuspicious
McAfeeVBObfus.ek
MAXmalware (ai score=89)
VBA32Malware-Cryptor.VB.gen
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaW32/Vobfus.GEW.worm
ESET-NOD32Win32/AutoRun.VB.ASX
TrendMicro-HouseCallWORM_VOBFUS.SMAB
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!3SQJSMLrXEI
IkarusWorm.Win32.Vobfus
MaxSecureVirus.Virus.W32.VB.R5
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.34804.om0@aK227Fdi
AVGWin32:Regrun-MQ [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.0E83.Malware.Gen

How to remove Win32/AutoRun.VB.ASX?

Win32/AutoRun.VB.ASX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment