Malware

Should I remove “Win32/AutoRun.VB.AUI”?

Malware Removal

The Win32/AutoRun.VB.AUI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AUI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AUI?


File Info:

name: 430D0D615AB7CE5C2D90.mlw
path: /opt/CAPEv2/storage/binaries/45e556d2726ca8df137902c3dbc494862029af70ff14f7055bb81f4e16b23b3e
crc32: 96A6A294
md5: 430d0d615ab7ce5c2d9087c1e4547558
sha1: 6e622f3740f9abf63f64db256169bb6b2a0319b1
sha256: 45e556d2726ca8df137902c3dbc494862029af70ff14f7055bb81f4e16b23b3e
sha512: 7f18cb05254000e5f63e5c3c38d82df0e0f11736b781421fab8fd02cb460df3b8d40da7ab4af616e19142c0bda0ad715a4fe67449e6140679477a6fb607b96bd
ssdeep: 1536:pNQBHrf6cO/hr0kGulSc16l6u+NMMl/KlYv1Tq5ThFfNIjnZ2d:ughrllu8CFFfCnId
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FA3806737051468E978663423BB8AE739F3A89D0A1B65437B3436385C3FE422D25BD3
sha3_384: ec853563ed427befa2a7bf5e97c6f85d5970dd286af637bbed8ce703dcdfcdeb6a675851f17aabc840754d8a1fde7364
ep_bytes: 6820124000e8eeffffff000000000000
timestamp: 2012-04-05 20:59:20

Version Info:

Translation: 0x0409 0x04b0
ProductName: SkheOtKI
FileVersion: 1.00
ProductVersion: 1.00
InternalName: vJYhvyvLkF
OriginalFilename: vJYhvyvLkF.exe

Win32/AutoRun.VB.AUI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lvqp
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.14616
MicroWorld-eScanTrojan.GenericKDZ.82987
ClamAVWin.Trojan.VB-1687
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.nm
McAfeeW32/Autorun.worm.aaeh
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.740f9a
BitDefenderThetaAI:Packer.FFF3D4E120
VirITTrojan.Win32.VBCrypt.FAJ
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AUI
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.VBNA.baij
BitDefenderTrojan.GenericKDZ.82987
NANO-AntivirusTrojan.Win32.VB.rilpe
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACFA [Trj]
TencentWorm.Win32.Vobfus.h
TACHYONWorm/W32.VBNA.98304
EmsisoftTrojan.GenericKDZ.82987 (B)
F-SecureTrojan.TR/Jorik.vbaayu
BaiduWin32.Worm.AutoRun.bc
VIPRETrojan.GenericKDZ.82987
TrendMicroWORM_VOBFUS.SMJA
FireEyeGeneric.mg.430d0d615ab7ce5c
SophosW32/Vobfus-AA
IkarusTrojan.Win32.Vobfus
GDataWin32.Worm.Vobfus.H
JiangminWorm.WBNA.iiaj
GoogleDetected
AviraTR/Jorik.vbaayu
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1442B
ZoneAlarmWorm.Win32.VBNA.baij
MicrosoftWorm:Win32/Vobfus!pz
VaristW32/VBInject.CO.gen!Eldorado
AhnLab-V3Worm/Win32.VBNA.R23055
Acronissuspicious
VBA32Worm.WBNA
ALYacTrojan.GenericKDZ.82987
MAXmalware (ai score=89)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingWorm.Vobfus!1.99C5 (CLASSIC)
YandexTrojan.GenAsa!NJz+QeX5uVg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.SuperThreat.m
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACFA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/AutoRun.VB.AUI?

Win32/AutoRun.VB.AUI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment