Malware

How to remove “Win32/AutoRun.VB.ATG”?

Malware Removal

The Win32/AutoRun.VB.ATG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ATG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ATG?


File Info:

name: 6738B8C47FFCF0F32848.mlw
path: /opt/CAPEv2/storage/binaries/45d69342e101430aec32ff02f24077195a15d490d26a7c9d5d8ce6d6dede813c
crc32: 32EAA8F5
md5: 6738b8c47ffcf0f32848d7892637a55c
sha1: f44df9709a34e1c72531b926d0476a81b21865f6
sha256: 45d69342e101430aec32ff02f24077195a15d490d26a7c9d5d8ce6d6dede813c
sha512: 30f8565c6f4792cfe5dcd6944de07444523fd795997560b6764368389405c8e24be2006cdc0208efa273768aaf57575567770f05783baf95aec680c9aa063caa
ssdeep: 3072:tJsv/cQPGDQicxBrGB+GJuyGI/YL1oxR8gXQi:tJscQP4aGjQyM1yJgi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14814A33A7290A73ED425C7F87CAE83A4502DAD3511C5A417F7C12B1A72E2AF79220767
sha3_384: 2798c30638189f581c0dfab238e8571c1e3c19791b825285a87aea650dda8162ee5984cf98d3985aa4429d544c3a538e
ep_bytes: 6850434000e8f0ffffff000000000000
timestamp: 2012-03-14 07:48:39

Version Info:

FileVersion: 3.00
ProductVersion: 3.00
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.ATG also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lv1H
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.21812
FireEyeGeneric.mg.6738b8c47ffcf0f3
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGeneric VB.kk
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1469552
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.fcbb92a6
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.47ffcf
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.SHeur4.UJB
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ATG
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMD1
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dgkf
BitDefenderGen:Variant.Symmi.21812
NANO-AntivirusTrojan.Win32.VB.cihugc
AvastWin32:VB-ABRW [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.Vobfus.200704.C
SophosMal/SillyFDC-AC
F-SecureWorm.WORM/VBNA.bztzre
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Symmi.21812
TrendMicroWORM_VOBFUS.SMD1
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.21812 (B)
IkarusWorm.Win32.Vobfus
JiangminTrojan/Vbobf.b
GoogleDetected
AviraWORM/VBNA.bztzre
VaristW32/Vobfus.AD.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.gen!R
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Symmi.D5534
ViRobotWorm.Win32.A.WBNA.200704.BQ
ZoneAlarmWorm.Win32.Vobfus.dgkf
GDataGen:Variant.Symmi.21812
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R22840
Acronissuspicious
VBA32BScope.Trojan.VB.Onechki
ALYacGen:Variant.Symmi.21812
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.Autorun!8.50 (TFE:3:NUyINK2O6IT)
YandexTrojan.GenAsa!hW3s5gOKwOE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36802.mm0@am9Vj7ji
AVGWin32:VB-ABRW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Vobfus.dgkf

How to remove Win32/AutoRun.VB.ATG?

Win32/AutoRun.VB.ATG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment