Malware

Win32/AutoRun.VB.ATF removal tips

Malware Removal

The Win32/AutoRun.VB.ATF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ATF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ATF?


File Info:

name: 50D46C3E467AE94AFECF.mlw
path: /opt/CAPEv2/storage/binaries/99d43a92283fa769564e4b5ae63270758ad8405aca45ecc1818046bb69056a30
crc32: 02201F02
md5: 50d46c3e467ae94afecfaaefb6c9963a
sha1: 1b886d13b5d10fda2fb8aea48acca88c1e2c88c6
sha256: 99d43a92283fa769564e4b5ae63270758ad8405aca45ecc1818046bb69056a30
sha512: fb0ce0ec2c2c2e0b009ab758af67683130e1ebb591353cee033cad4582068cf7032580ecc07fb7ef94fccd6197a97c03e224cada523f79c591f0eb249daac7b1
ssdeep: 3072:Iu+HtD517TWor5J80AisM/8jp6tdlWbRVslWQifgO4F07lD:Ix7TWqJlRsM/8E/IbRuLifI07
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15814C53A6390E33EE525C7F92CAA8364406DAD3505D1A417F7C22B1A76F1AF7D220397
sha3_384: 679e25722bb32aff7664501ed1c2d0ad02c06e2c8f659b09a4cf17f279493cc77809a96db40dce88395e0e775fb45ff5
ep_bytes: 6824434000e8f0ffffff000040000000
timestamp: 2012-03-13 22:12:33

Version Info:

FileVersion: 2.00
ProductVersion: 2.00
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.ATF also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.81
MicroWorld-eScanGen:Variant.Barys.431721
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeGeneric VB.kk
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36804.mm0@aG7!!3hi
VirITTrojan.Win32.Zyx.IX
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ATF
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMJA
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.efje
BitDefenderGen:Variant.Barys.431721
NANO-AntivirusTrojan.Win32.WBNA.crgjlc
SUPERAntiSpywareTrojan.Agent/Gen-Autorun[VB]
AvastWin32:VB-ABYV [Wrm]
TencentWorm.Win32.Vobfus.kt
EmsisoftGen:Variant.Barys.431721 (B)
F-SecureWorm.WORM/Vobfus.R.23
BaiduWin32.Trojan.VBObfus.f
VIPREGen:Variant.Barys.431721
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.50d46c3e467ae94a
SophosMal/SillyFDC-W
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
JiangminWorm.Vobfus.jdoj
WebrootW32.Worm.Bktr
GoogleDetected
AviraWORM/Vobfus.R.23
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.D69669
ViRobotWorm.Win32.A.WBNA.208896.D
ZoneAlarmWorm.Win32.Vobfus.efje
GDataGen:Variant.Barys.431721
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R27300
Acronissuspicious
VBA32BScope.Trojan.VB.Onechki
ALYacGen:Variant.Barys.431721
TACHYONWorm/W32.Vobfus.208896.B
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!hW3s5gOKwOE
IkarusTrojan.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABYV [Wrm]
DeepInstinctMALICIOUS

How to remove Win32/AutoRun.VB.ATF?

Win32/AutoRun.VB.ATF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment