Malware

Win32/AutoRun.VB.AVI removal instruction

Malware Removal

The Win32/AutoRun.VB.AVI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AVI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AVI?


File Info:

name: 82025C22E15BEB55C68E.mlw
path: /opt/CAPEv2/storage/binaries/15f3fa98221f2e74711b74f81cf2fb12ad004063c8ec999c14da85423f83cbb5
crc32: D4EC59C0
md5: 82025c22e15beb55c68ea3fe0269ebeb
sha1: ce83d98cb4ca4b2eb561c4d43117e3db0e6c8d4a
sha256: 15f3fa98221f2e74711b74f81cf2fb12ad004063c8ec999c14da85423f83cbb5
sha512: cd3f54c7325cfef0030f75b1c0e1da69c28168faf943dc6d9397a3b1722a894d2a16f05149b11ab033087c917de768a32c9379a74cc487879069ea21ca13f766
ssdeep: 6144:AQ3PFKs78g2KyEOaWEqxF6snji81RUinKdNOAs:zPh+mFC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E34E9573B61A889F128197059F3C3F237D6EC4D4A47424F9B203A2F2EBEE651D24663
sha3_384: bd3f046046ec77d37eb21d645fb7b9aac63ef713d03bee48bb3986690d1cb67584c13f5ea8e02318f4eff782253a067b
ep_bytes: 6848124000e8eeffffff000000000000
timestamp: 2012-04-30 23:20:24

Version Info:

Translation: 0x0409 0x04b0
ProductName: ajxsvpfhzdo
FileVersion: 7.08.0002
ProductVersion: 7.08.0002
InternalName: uhuiagjllq
OriginalFilename: uhuiagjllq.exe

Win32/AutoRun.VB.AVI also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.95268
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dt
McAfeeVBObfus.dv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.2e15be
BaiduWin32.Worm.AutoRun.bl
VirITTrojan.Win32.VBCrypt.EVJ
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AVI
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIJ
ClamAVWin.Trojan.Vobfus-76
KasperskyWorm.Win32.WBNA.ipa
BitDefenderTrojan.GenericKDZ.95268
NANO-AntivirusTrojan.Win32.Jorik.cqkxvn
AvastWin32:Agent-AXNX [Trj]
TencentWorm.Win32.Vobfus.f
EmsisoftTrojan.GenericKDZ.95268 (B)
GoogleDetected
F-SecureTrojan.TR/Barys.11258258
DrWebWin32.HLLW.Autoruner1.15280
VIPRETrojan.GenericKDZ.95268
TrendMicroWORM_VOBFUS.SMIJ
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.82025c22e15beb55
SophosMal/VBCheMan-J
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.hpyw
VaristW32/Vobfus.O.gen!Eldorado
AviraTR/Barys.11258258
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.998
MicrosoftWorm:Win32/AutoRun!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D17424
ZoneAlarmWorm.Win32.WBNA.ipa
GDataTrojan.GenericKDZ.95268
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R24466
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.om0@ai00Pbhi
ALYacTrojan.GenericKDZ.95268
TACHYONWorm/W32.WBNA.237568
VBA32SScope.Malware-Cryptor.VBCR.3042
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingTrojan.FakeIcon!1.64A2 (CLASSIC)
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Jorik.EGLG!tr
AVGWin32:Agent-AXNX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Autorun.f8cd8700

How to remove Win32/AutoRun.VB.AVI?

Win32/AutoRun.VB.AVI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment