Malware

About “Win32/AutoRun.VB.AUA” infection

Malware Removal

The Win32/AutoRun.VB.AUA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AUA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AUA?


File Info:

name: 76D9FDAF90F7A0DB53B3.mlw
path: /opt/CAPEv2/storage/binaries/f6d55c86f9def85dd3102101e7c53a09332bc18babecbd72a0b8ed494ee0a6d1
crc32: 80F009EE
md5: 76d9fdaf90f7a0db53b352306ecd282a
sha1: 8e6ae506d90483dff770f66bbeb534dc93d0aa79
sha256: f6d55c86f9def85dd3102101e7c53a09332bc18babecbd72a0b8ed494ee0a6d1
sha512: 9108a0458fb0f96f53f3ecec58daf4627e057f84c1d5d77350152187b11432522199e9f2e98c8413811189c1ec792b8add0261599d9a6385dc113f3779365304
ssdeep: 6144:yMJd4Psq8gFV91GGGLVTmrshXj0MQH1DUhu1GJu+DODryKnKxO:56UgFV6Hm1JKxO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128643016AD10A03BE64698F1291983AA291D1E776380FC0BF385BB9870751E7F6F171F
sha3_384: 6887b1f5bf1f790f97dbea0a76511bea8ceadcead8afa3115443e6453ca2b8bf517cbca141c0b75984ec782f5ae0a5f6
ep_bytes: 68dc4b4000e8f0ffffff000048000000
timestamp: 2012-03-29 20:56:00

Version Info:

ProductName: 87
FileVersion: 67.00
ProductVersion: 188.00
InternalName: 445
OriginalFilename: 98
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.AUA also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.dv
MalwarebytesMalware.AI.3346315863
VIPREGen:Variant.Barys.950
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f90f7a
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.SHeur4.WOC
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AUA
APEXMalicious
ClamAVWin.Trojan.Vobfus-8
KasperskyWorm.Win32.Vobfus.dffg
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.VB.rilrg
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACAJ [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Otran.A.7622
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMJA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.76d9fdaf90f7a0db
SophosMal/SillyFDC-W
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.VB.ABW
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Otran.A.7622
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Barys.950
ViRobotTrojan.Win32.A.VB.323584.C
ZoneAlarmWorm.Win32.Vobfus.dffg
MicrosoftWorm:Win32/Vobfus.gen!X
CynetMalicious (score: 100)
AhnLab-V3HEUR/Fakon.mwf.X1381
BitDefenderThetaGen:NN.ZevbaF.36196.tm0@aauLgrgi
ALYacGen:Variant.Barys.950
TACHYONTrojan/W32.VB-Agent.323584.AA
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingTrojan.VBEx!1.99EE (CLASSIC)
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ACAJ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/AutoRun.VB.AUA?

Win32/AutoRun.VB.AUA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment