Malware

About “Win32/AutoRun.VB.AVF” infection

Malware Removal

The Win32/AutoRun.VB.AVF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AVF virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
ns1.musiczipz.com
ns1.musicmixa.net
ns1.musicmixa.org
ns1.musicmixb.co
ns1.musicmixc.com

How to determine Win32/AutoRun.VB.AVF?


File Info:

crc32: 018B8843
md5: 634cba9f7a933897e47e1e0458eae561
name: 634CBA9F7A933897E47E1E0458EAE561.mlw
sha1: 8e4ed0ec745a743a08be6c23723ed90710bc873f
sha256: da95e7ddf708ba777092f0a18eb9070619a1005062e851d4516d0c9a3cad6341
sha512: 36633630a3b2d249dc52fdff57bbe33e7fe16946b6e04d6820ea7205733da54398cc44b5c42a0f5fbaa5b7cac698ef82ebe52f297f2b2ac532d05224b6cfd91b
ssdeep: 3072:CyqtY20tQ9nLHbB9WJvA7DejJuKvEhfmH1e:t24QxL7B9WSvejJuB+0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 7.08.0002
InternalName: tvpysnohrqvv
FileVersion: 7.08.0002
OriginalFilename: tvpysnohrqvv.exe
ProductName: bzfdmdi

Win32/AutoRun.VB.AVF also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.dv
CylanceUnsafe
VIPRETrojan.Win32.Vobfus.a (v)
SangforMalware
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.VBInject.11
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f7a933
BaiduWin32.Worm.VB.mf
CyrenW32/Vobfus.AP.gen!Eldorado
SymantecW32.Changeup
TotalDefenseWin32/Vobfus.O!generic
APEXMalicious
AvastWin32:VB-ADDH [Trj]
ClamAVWin.Trojan.VBTrojan3-6118226-0
KasperskyTrojan.Win32.VB.budw
NANO-AntivirusTrojan.Win32.VB.rilpg
ViRobotTrojan.Win32.A.VB.200704.H
Ad-AwareGen:Variant.VBInject.11
EmsisoftGen:Variant.VBInject.11 (B)
ComodoWorm.Win32.Pronny.AK@4ogvoo
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.15097
ZillyaWorm.WBNAGen.Win32.15
TrendMicroWORM_VOBFUS.SME
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
MaxSecureTrojan.VB.budw
FireEyeGeneric.mg.634cba9f7a933897
SophosML/PE-A + Mal/VBCheMan-G
SentinelOneStatic AI – Malicious PE – Worm
JiangminTrojan/VB.clfr
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftVirTool:Win32/VBInject.WX
ArcabitTrojan.VBInject.11
SUPERAntiSpywareTrojan.Agent/Gen-Autorun[VB]
ZoneAlarmTrojan.Win32.VB.budw
GDataGen:Variant.VBInject.11
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R40142
Acronissuspicious
VBA32SScope.Malware-Cryptor.VBCR.3042
ALYacGen:Variant.VBInject.11
TACHYONWorm/W32.WBNA.200704.D
MalwarebytesVobfus.Worm.Evasion.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/AutoRun.VB.AVF
TrendMicro-HouseCallWORM_VOBFUS.SME
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!dMYWIGcmXQw
IkarusVirus.Win32.Cryptor
eGambitUnsafe.AI_Score_100%
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.34804.mm0@aqVGL2ji
AVGWin32:VB-ADDH [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.0510.Malware.Gen

How to remove Win32/AutoRun.VB.AVF?

Win32/AutoRun.VB.AVF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment