Malware

Win32/AutoRun.VB.AVN removal instruction

Malware Removal

The Win32/AutoRun.VB.AVN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AVN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.AVN?


File Info:

name: BB14F2330A6B81731526.mlw
path: /opt/CAPEv2/storage/binaries/880b81382edadec38295c870f50e48c5772b8d32f145ee61ea64952fb259e7be
crc32: B2FFA31B
md5: bb14f2330a6b8173152684e327674a5b
sha1: 263562274d3f532e1a16b5a4aca220a43d5c1791
sha256: 880b81382edadec38295c870f50e48c5772b8d32f145ee61ea64952fb259e7be
sha512: 04385dc2fd156babc26d12ad4a8bce082f5eb988bae6bf3b27f74419712fc8d99fdb993eda5b1701faf41efeb913c54861f509d0dfc81b6c82a252c0c985478c
ssdeep: 6144:+KO33dwqsNy5ibpNjl4EqxF6snji81RUinKICCF:rOHdQxlU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10534D7A77B719888F418157058F3D3F23796EC4D494B520B2B243E2A3FBBE652D24A53
sha3_384: 03595a74401330d5da1d0fd8075973b9b6775c175839ddf941881a2694748303a01f27c492b07ceb2f06169ffc0ef599
ep_bytes: 688c124000e8eeffffff000000000000
timestamp: 2012-05-04 05:48:36

Version Info:

Translation: 0x0409 0x04b0
ProductName: jpplyry
FileVersion: 7.08.0002
ProductVersion: 7.08.0002
InternalName: lfjadwyqol
OriginalFilename: lfjadwyqol.exe

Win32/AutoRun.VB.AVN also known as:

LionicTrojan.Win32.Vobfus.lL56
tehtrisGeneric.Malware
DrWebTrojan.MulDrop3.48626
MicroWorld-eScanTrojan.GenericKDZ.98339
FireEyeGeneric.mg.bb14f2330a6b8173
CAT-QuickHealTrojan.Beebone.D
ALYacTrojan.GenericKDZ.98339
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.192ad950
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.30a6b8
BitDefenderThetaGen:NN.ZevbaF.36196.om0@aWC@B8bi
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AVN
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.sln
BitDefenderTrojan.GenericKDZ.98339
NANO-AntivirusTrojan.Win32.Vobfus.cqkxvu
ViRobotTrojan.Win32.A.VB.233472.O
TencentWorm.Win32.Vobfus.n
SophosW32/Vobfus-AN
F-SecureWorm.WORM/Vobfus.ew.jh
BaiduWin32.Worm.Autorun.af
VIPRETrojan.GenericKDZ.98339
TrendMicroWORM_VOBFUS.SM00
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dt
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.98339 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraWORM/Vobfus.ew.jh
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D18023
SUPERAntiSpywareTrojan.Agent/Gen-Vban
ZoneAlarmTrojan.Win32.Vobfus.sln
GDataTrojan.GenericKDZ.98339
TACHYONTrojan/W32.Vobfus.233472
AhnLab-V3Trojan/Win32.VB.R24629
McAfeeVBObfus.dv
MAXmalware (ai score=89)
VBA32SScope.Malware-Cryptor.VBCR.3042
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingTrojan.FakeIcon!1.64A2 (CLASSIC)
YandexTrojan.GenAsa!vv6zMG0Mexk
IkarusWorm.Vobfus
FortinetW32/Jorik.EGLG!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.AVN?

Win32/AutoRun.VB.AVN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment