Malware

Win32/AutoRun.VB.AUM malicious file

Malware Removal

The Win32/AutoRun.VB.AUM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AUM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AUM?


File Info:

name: DB2A38039F2C76D0CE1F.mlw
path: /opt/CAPEv2/storage/binaries/2793cee3b14c8dbec6911afc700c329a503e4a9e06c24c4c50ae4c6b3f5071c8
crc32: 5DDB1976
md5: db2a38039f2c76d0ce1f26f49b79dfc3
sha1: 2e11eebb763a6793672eb32eb304fcc472277c4f
sha256: 2793cee3b14c8dbec6911afc700c329a503e4a9e06c24c4c50ae4c6b3f5071c8
sha512: 5596d9b145bac29e261462808a9bc78f96d71ac07aaaa85e80973a4c80562a9d559680c853eff7928a7efa45ec7283c8ad39346dcea2c812575d49b2d022c15c
ssdeep: 1536:OOJzB5YS1hRF/N69Be3O4Ga+FE1jKKvRgrkOSoqPNeG0h/y:zxvYS1h3FoI3O41+F0kSjIq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111C3FDAAFB82107DF156017C16DAE6E337A57805DD6BD08ABB34B2A40CDAD1108FD763
sha3_384: ce7618655e1c6815b512fbb860d89bcdcda1dd308a067d8c12ea4a56437cd38c45636eba3873919967a44cb40b790316
ep_bytes: 6880124000e8eeffffff000048000000
timestamp: 2012-04-10 22:05:35

Version Info:

0: [No Data]

Win32/AutoRun.VB.AUM also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.74379
FireEyeGeneric.mg.db2a38039f2c76d0
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGeneric VB.kk
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.JorikGen.Win32.1
CynetMalicious (score: 100)
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.39f2c7
BitDefenderThetaGen:NN.ZevbaF.36802.hmW@au5evIli
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AUM
APEXMalicious
ClamAVWin.Dropper.XtremeRAT-7708589-0
KasperskyTrojan.Win32.Jorik.Vobfus.ajrc
BitDefenderTrojan.GenericKDZ.74379
NANO-AntivirusTrojan.Win32.Jorik.covkks
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACHG [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftTrojan.GenericKDZ.74379 (B)
BaiduWin32.Worm.Autorun.u
F-SecureTrojan.TR/Jorik.Vobfus.ajr
DrWebWin32.HLLW.Autoruner2.29121
VIPRETrojan.GenericKDZ.74379
TrendMicroWORM_VOBFUS.SMC
Trapminemalicious.high.ml.score
SophosTroj/Vb-FWD
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.AM.gen!Eldorado
AviraTR/Jorik.Vobfus.ajr
MAXmalware (ai score=86)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.AutoRun.AMH@4owee9
ArcabitTrojan.Generic.D1228B
ViRobotWorm.Win32.A.VBNA.126976.BB
ZoneAlarmTrojan.Win32.Jorik.Vobfus.ajrc
GDataWin32.Trojan.PSE.KS2CXQ
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R23505
Acronissuspicious
VBA32SScope.Malware-Cryptor.VBCR.1141
ALYacTrojan.GenericKDZ.74379
TACHYONWorm/W32.Vobfus.126976
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMC
RisingWorm.Vobfus!1.99C6 (CLASSIC)
YandexTrojan.GenAsa!NQ5jghRmwiA
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACHG [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Vobfus.a28e8569

How to remove Win32/AutoRun.VB.AUM?

Win32/AutoRun.VB.AUM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment