Malware

How to remove “Win32/AutoRun.VB.AUN”?

Malware Removal

The Win32/AutoRun.VB.AUN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AUN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AUN?


File Info:

name: 31EA091C0C844984E0BD.mlw
path: /opt/CAPEv2/storage/binaries/b8675447028c3aeb149b86c892f1554f1fd773e3124f1576431cf561de772962
crc32: 2F4FD7FE
md5: 31ea091c0c844984e0bdc17c76b8f6f3
sha1: 117f39773615b046d154c8da6c21b1cce917f743
sha256: b8675447028c3aeb149b86c892f1554f1fd773e3124f1576431cf561de772962
sha512: 37373b7f75b50ca9e4865f3b9528ac801a212f84ea3a82427abaca0a87f8fea49cf596838925c520a293958e50b4df3b2d2a4124b1ca8d0232f1154ac90284b6
ssdeep: 1536:iF1si40NhgIuFQFvHwd6PXOYb7gXWgWKsEHfNeG0h/E:+1sivg/FQByYb7gvsEYM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9D320A9FB82807DF55A113C13EAE6E325B634458D6FD08AB734B3A404DAD1188FD763
sha3_384: 6d4246fe75642ff56fbb8d89a35b244ea3fa8ce6663f90ade2548cd7993dd3950e7d24048536fab7f9f39bb947c2f58d
ep_bytes: 6880124000e8eeffffff000048000000
timestamp: 2012-04-11 19:29:09

Version Info:

0: [No Data]

Win32/AutoRun.VB.AUN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.95603
ClamAVWin.Dropper.XtremeRAT-7708589-0
FireEyeGeneric.mg.31ea091c0c844984
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacTrojan.GenericKDZ.95603
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.76688
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/Vobfus.97ea32d3
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Autorun.u
VirITTrojan.Win32.Cryptor.RR
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AUN
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.axgu
BitDefenderTrojan.GenericKDZ.95603
NANO-AntivirusTrojan.Win32.VB.cmtitt
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACHW [Trj]
TencentWorm.Win32.Vobfus.gaq
TACHYONWorm/W32.Vobfus.131072
SophosMal/VBCheMan-J
F-SecureTrojan.TR/Otran.A.800
DrWebWin32.HLLW.Autoruner1.15105
VIPRETrojan.GenericKDZ.95603
TrendMicroWORM_VOBFUS.SM41
EmsisoftTrojan.GenericKDZ.95603 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.95603
JiangminWorm.Vobfus.jtc
WebrootW32.Worm.Ej
GoogleDetected
AviraTR/Otran.A.800
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.AutoRun.AMH@4owee9
ArcabitTrojan.Generic.D17573
ViRobotWorm.Win32.A.VBNA.131072.BY
ZoneAlarmWorm.Win32.Vobfus.axgu
MicrosoftWorm:Win32/Vobfus!pz
VaristW32/Vobfus.AN.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R23505
Acronissuspicious
McAfeeW32/Autorun.worm.aaeh
MAXmalware (ai score=100)
VBA32SScope.Malware-Cryptor.VBCR.1141
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM41
RisingWorm.Vobfus!1.99C6 (CLASSIC)
YandexTrojan.GenAsa!XRHX5NhasMM
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36744.imW@a8bmiNmi
AVGWin32:VB-ACHW [Trj]
Cybereasonmalicious.73615b
DeepInstinctMALICIOUS

How to remove Win32/AutoRun.VB.AUN?

Win32/AutoRun.VB.AUN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment