Malware

Win32/AutoRun.VB.AUL (file analysis)

Malware Removal

The Win32/AutoRun.VB.AUL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AUL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AUL?


File Info:

name: 5D82A8D9B9784A524E92.mlw
path: /opt/CAPEv2/storage/binaries/fe078b31f144470ff9ecfcd00e4887a824e9b0f45cf734143f26fa456e25f82f
crc32: 52AA986E
md5: 5d82a8d9b9784a524e92cf842ad19871
sha1: f9af205832d97b43a4e67f8f6eebad040c11b82d
sha256: fe078b31f144470ff9ecfcd00e4887a824e9b0f45cf734143f26fa456e25f82f
sha512: baff17fe355e2b37b824bfc7277a19e82de5c15345dd490f4ddd6a4b33713f42d483d595c5ef4d33142a239520f1df6d870e5a6abb8d500b81275722c0b51cbc
ssdeep: 1536:zeH0cL3BndebZO9+dGrNsjmJzNuKuFr1u5BRQbCcIa:G3BdKZO9+VjO+v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9043E9F7FF52244F9580638ADF396FE19D2A98C7A1B4142673036641BEFE021C24A5F
sha3_384: 8e2cbc3132bfea6992d84e1e5ff67058c5c84ceda542a9c9f0cea8bc9a0d894356af6a289402468cc7482d54d408c24d
ep_bytes: 6894124000e8f0ffffff000048000000
timestamp: 2012-04-09 22:21:33

Version Info:

Translation: 0x0409 0x04b0
ProductName: qUHPuz
FileVersion: 1.00
ProductVersion: 1.00
InternalName: JgUwyp
OriginalFilename: JgUwyp.exe

Win32/AutoRun.VB.AUL also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.Generic.cz
McAfeeGeneric VB.kk
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.950
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.9b9784
BitDefenderThetaGen:NN.ZevbaF.36802.lq0@aynzIpei
VirITTrojan.Win32.Generic.CKVZ
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AUL
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMJA
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.ablx
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Jorik.cihugs
SUPERAntiSpywareWorm.Vobfus
AvastWin32:VB-ACGR [Trj]
TencentTrojan.Win32.Jorik.pa
EmsisoftGen:Variant.Barys.950 (B)
BaiduWin32.Worm.VB.nn
F-SecureTrojan.TR/Jorik.Vobfu.ahpj
DrWebWin32.HLLW.Autoruner1.14788
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5d82a8d9b9784a52
SophosW32/Vobfus-AH
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.glab
ALYacGen:Variant.Barys.950
VaristW32/Vobfus.AJ.gen!Eldorado
AviraTR/Jorik.Vobfu.ahpj
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.VBNA.102400.BA
ZoneAlarmWorm.Win32.Vobfus.ablx
GDataWin32.Trojan.PSE1.8A9OXW
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R150635
Acronissuspicious
VBA32Trojan.Jorik
GoogleDetected
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!n9vpFGRhqIs
IkarusTrojan.Win32.Jorik
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACGR [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.efae4ae2

How to remove Win32/AutoRun.VB.AUL?

Win32/AutoRun.VB.AUL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment