Malware

About “Win32/AutoRun.VB.ATX” infection

Malware Removal

The Win32/AutoRun.VB.ATX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ATX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.ATX?


File Info:

name: DBB99B1A855224B6869A.mlw
path: /opt/CAPEv2/storage/binaries/abcd1727340f9bab1802b5a6b6be89a118bc6f04d86484d7691d528ef219b30a
crc32: D116B428
md5: dbb99b1a855224b6869a8d7ebef4a9c1
sha1: 3af1dc4e929766b920bc3b643a4b7f7d5f426c8f
sha256: abcd1727340f9bab1802b5a6b6be89a118bc6f04d86484d7691d528ef219b30a
sha512: 7d25b6090e29faea8eeb13e56ae3781d529ec32283dd7c1dc60fa61f26f63de2c98e1d7c5b4b73fda6f1d51fa91e2ad5c9d49683bbb6e68e9507f0317b498d51
ssdeep: 6144:8d7CGWUsbNZeoq6AvFPpWlyfeWgdx1XxcNoX+poNd8m3RZWuAzgGk:8bWUsbbeoq6AFpWlyfeWgdx1Xxq4+pob
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D94461696290B73DE424C2F968474390886DED361498B80BFBD27B1971F1DE7E3207A7
sha3_384: f1f35f768edf9e969d73b8ee065eb68d9a74ac799eb066c79cc8eab50e95bc8a36f4823df1a2e894a49dea4a728709ec
ep_bytes: 68dc404000e8eeffffff000000000000
timestamp: 2012-03-27 05:23:16

Version Info:

ProductName: 66
FileVersion: 61.00
ProductVersion: 61.00
InternalName: 67
OriginalFilename: 67
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.ATX also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lRM0
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.60
MicroWorld-eScanGen:Variant.Barys.950
ClamAVWin.Trojan.VB-73708
FireEyeGeneric.mg.dbb99b1a855224b6
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.950
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Vobfus.Win32.1347808
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Vobfus.4413cc92
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36662.pm0@a4cLB1bi
VirITTrojan.Win32.SHeur4.WDC
CyrenW32/Vobfus.AD.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ATX
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dgmz
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Jorik.cojaep
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABZH [Trj]
RisingWorm.VobfusEx!1.99DB (CLASSIC)
TACHYONTrojan/W32.VB-Agent.258048.CJ
SophosMal/SillyFDC-W
F-SecureTrojan.TR/Jorik.Vobfus.yfl
BaiduWin32.Trojan.Inject.n
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SMIJ
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Barys.950 (B)
IkarusWorm.Win32.Vobfus
GDataGen:Variant.Barys.950
WebrootTrojan.Win32.Diple
AviraTR/Jorik.Vobfus.yfl
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.WBNA.258048.PV
ZoneAlarmWorm.Win32.Vobfus.dgmz
MicrosoftWorm:Win32/Vobfus.gen!R
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R22928
Acronissuspicious
McAfeeVBObfus.dv
MAXmalware (ai score=87)
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMIJ
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!82ZpTVC+PrE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABZH [Trj]
DeepInstinctMALICIOUS

How to remove Win32/AutoRun.VB.ATX?

Win32/AutoRun.VB.ATX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment