Malware

Win32/AutoRun.VB.AUI removal tips

Malware Removal

The Win32/AutoRun.VB.AUI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AUI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AUI?


File Info:

name: F08B9584680A95C92C00.mlw
path: /opt/CAPEv2/storage/binaries/1f447776dd475d1ea77dcfb055494041bb6513966123d43cc17dc5e8073ed4d3
crc32: B966FDEF
md5: f08b9584680a95c92c00ab4c8a6f7a3e
sha1: 5310c96f78fde7b7fc95cf59865ab2440d179c40
sha256: 1f447776dd475d1ea77dcfb055494041bb6513966123d43cc17dc5e8073ed4d3
sha512: af0270a26d7fbc606c8e113efd7b6f80548e5cdf42e660873af1d0b07dfc476ca6f15412f6dea9d1ae2be1c09d8edce27f886f36163366f79720a90c6033f8fa
ssdeep: 1536:KbQBH1f6cO/h0kGulSc16l6u+NMMl/KlYv1Tq5ThFfNIjnZRu:B2hllu8CFFfCnju
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178A3816737451468E978663423BB8AE735F3A89C0A1B66437B3436385C3FE422D25BD3
sha3_384: 7d7073e71ade94996e8dfbb4ae930da0a30313cf1d93b7746e2901e30ef4000622b4ec007d811d1bda8cce47fab88d88
ep_bytes: 6820124000e8eeffffff000000000000
timestamp: 2012-04-05 20:59:20

Version Info:

Translation: 0x0409 0x04b0
ProductName: gvhjauXk
FileVersion: 1.00
ProductVersion: 1.00
InternalName: tRmFikLxts
OriginalFilename: tRmFikLxts.exe

Win32/AutoRun.VB.AUI also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-ACFA [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.82987
FireEyeGeneric.mg.f08b9584680a95c9
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.nm
McAfeeGeneric VB.kk
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.4680a9
BaiduWin32.Worm.AutoRun.bc
VirITTrojan.Win32.VBCrypt.FAJ
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AUI
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1687
KasperskyWorm.Win32.VBNA.baij
BitDefenderTrojan.GenericKDZ.82987
NANO-AntivirusTrojan.Win32.VB.rilpe
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACFA [Trj]
TencentWorm.Win32.Vobfus.h
TACHYONWorm/W32.VBNA.98304
EmsisoftTrojan.GenericKDZ.82987 (B)
F-SecureTrojan.TR/Jorik.vbaayu
DrWebWin32.HLLW.Autoruner1.14616
VIPRETrojan.GenericKDZ.82987
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.high.ml.score
SophosW32/Vobfus-AA
IkarusTrojan.Win32.Vobfus
JiangminWorm.WBNA.iiaj
VaristW32/VBInject.CO.gen!Eldorado
AviraTR/Jorik.vbaayu
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1442B
ZoneAlarmWorm.Win32.VBNA.baij
GDataWin32.Worm.Vobfus.H
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R23055
Acronissuspicious
VBA32Worm.WBNA
ALYacTrojan.GenericKDZ.82987
MAXmalware (ai score=85)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingWorm.Vobfus!1.99C5 (CLASSIC)
YandexTrojan.GenAsa!NJz+QeX5uVg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.SuperThreat.m
FortinetW32/VBObfus.AU!tr
BitDefenderThetaAI:Packer.FFF3D4E120
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.a56de9bd

How to remove Win32/AutoRun.VB.AUI?

Win32/AutoRun.VB.AUI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment