Malware

Win32/AutoRun.VB.AUS information

Malware Removal

The Win32/AutoRun.VB.AUS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AUS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.AUS?


File Info:

name: DCD412D0BB62B9ECFA71.mlw
path: /opt/CAPEv2/storage/binaries/116ab7add53ac2cced0f13f5b313a02ee9f792b1d0f7eb7117d3bac50a56905e
crc32: 8AB9DC77
md5: dcd412d0bb62b9ecfa71c6ffd0795338
sha1: b40a30382e699497ed13aa92cdf7372cfdcedd8b
sha256: 116ab7add53ac2cced0f13f5b313a02ee9f792b1d0f7eb7117d3bac50a56905e
sha512: 6ec93207cee127fa9e93fd23ff3ccae1374572e04d816624ceb5d40f74625c2637519b1e75edc84c5799b66c6688890444afcf3039af9b8c72671269d5a98c90
ssdeep: 1536:6gbhEFn/67NxkiQixA+alh98r8Y9USv1jyJxtFk7wo7J:PbhEFn/67gjH8ri8XwQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FCF3F7577B06404DD7543A7427EEC2D23792F4484F2B69C67AA4B1B8CCDAE211E34ACB
sha3_384: 63392370bdad3eb20be2df2cd963d4b0de9d9ee907a487db568931ab699940a48d6012410e1cfac94a044d27aa04456a
ep_bytes: 68a0124000e8f0ffffff000000000000
timestamp: 2001-02-27 23:41:40

Version Info:

0: [No Data]

Win32/AutoRun.VB.AUS also known as:

BkavW32.InsuLateF.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.7246
MicroWorld-eScanTrojan.GenericKDZ.96228
FireEyeGeneric.mg.dcd412d0bb62b9ec
CAT-QuickHealTrojan.Beebone.D
ALYacTrojan.GenericKDZ.96228
Cylanceunsafe
VIPRETrojan.GenericKDZ.96228
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
BitDefenderTrojan.GenericKDZ.96228
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.0bb62b
BitDefenderThetaGen:NN.ZevbaF.36196.kmZ@a88RW3o
VirITTrojan.Win32.Zyx.JT
CyrenW32/Vobfus.AO.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AUS
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Vobfus.hy
AlibabaWorm:Win32/vobfus.1030
NANO-AntivirusTrojan.Win32.VB.rexdn
ViRobotTrojan.Win32.A.VB.126976.W
RisingWorm.VobfusEx!1.99E1 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.96228
SophosW32/SillyFDC-HV
F-SecureTrojan.TR/Barys.629.jh.1
BaiduWin32.Worm.Autorun.v
TrendMicroTROJ_GEN.R002C0CEI23
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.96228 (B)
IkarusTrojan.Patched
AviraTR/Barys.629.jh.1
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.EL
XcitiumWorm.Win32.VB.AUB@4ol77w
ArcabitTrojan.Generic.D177E4
GDataTrojan.GenericKDZ.96228
GoogleDetected
AhnLab-V3Trojan/Win.VB.R567073
Acronissuspicious
McAfeeVBObfus.dv
TACHYONTrojan/W32.VB-Vobfus.163840.B
DeepInstinctMALICIOUS
VBA32SScope.Malware-Cryptor.VBCR.1641
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_GEN.R002C0CEI23
TencentTrojan.Win32.Vobfus.ka
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:GenMalicious-FAD [Trj]
AvastWin32:GenMalicious-FAD [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.AUS?

Win32/AutoRun.VB.AUS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment