Malware

How to remove “Win32/AutoRun.VB.AVO”?

Malware Removal

The Win32/AutoRun.VB.AVO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AVO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.AVO?


File Info:

name: A65CC7F9F698891B1489.mlw
path: /opt/CAPEv2/storage/binaries/00887836c20c86d09ba1495459157e32fe9790cd8f1aef3eb9fe524c7508b52c
crc32: CA6E4B57
md5: a65cc7f9f698891b1489f4076bccd0a2
sha1: 9f3083414f8b6ffd488163204dd8d3055d7589c5
sha256: 00887836c20c86d09ba1495459157e32fe9790cd8f1aef3eb9fe524c7508b52c
sha512: f483ce8110401acb7212327eb26d17301939f4ec06cd45d72f03dc942ef0543b608c40ba6f4ec62865b708d5ca9d93d10f34df1631f31a3ef7e0098ec2a5dc38
ssdeep: 1536:fvl0cc+BnwOB+dGrNjjmJ2NuKuFr1M5BK:a+BwOB++jOZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CA3B99F7BA11277FF780534A9F2B5FA1592A1CCEA0B414D772035E41ADAD023C2CA5B
sha3_384: 7a42f7ff7d24a18bcf6f7f8d17b48afb8c144d476df4a096e7aa829cd8347802a8344e9b6ec7a10cc3a239298caafe33
ep_bytes: 6894124000e8f0ffffff000048000000
timestamp: 1999-04-16 11:29:07

Version Info:

0: [No Data]

Win32/AutoRun.VB.AVO also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.14788
MicroWorld-eScanTrojan.GenericKDZ.82864
FireEyeGeneric.mg.a65cc7f9f698891b
CAT-QuickHealTrojan.Beebone.D
McAfeeW32/Autorun.worm.aaeh
Sangfor[MICROSOFT VISUAL BASIC V6.0]
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.9f6988
BitDefenderThetaGen:NN.ZevbaF.34606.gqW@aatrYTmi
VirITTrojan.Win32.Generic.CKVZ
CyrenW32/VBKrypt.BFE.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AVO
TrendMicro-HouseCallWORM_VOBFUS.SMJA
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.ahog
BitDefenderTrojan.GenericKDZ.82864
NANO-AntivirusTrojan.Win32.Jorik.cihugs
AvastWin32:VB-ACGS [Trj]
TencentTrojan.Win32.Jorik.pa
Ad-AwareTrojan.GenericKDZ.82864
SophosML/PE-A + W32/Vobfus-AH
ComodoWorm.Win32.VB.AUA@4o7zkg
BaiduWin32.Worm.VB.nn
TrendMicroWORM_VOBFUS.SMJA
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nm
EmsisoftTrojan.GenericKDZ.82864 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.82864
AviraTR/Jorik.Vobfus.ahog
MAXmalware (ai score=88)
ViRobotWorm.Win32.A.VBNA.102400.AZ
ZoneAlarmTrojan.Win32.Jorik.Vobfus.ahog
MicrosoftWorm:Win32/Vobfus.EH
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.Vobfus.R440143
Acronissuspicious
VBA32Trojan.Jorik
ALYacTrojan.GenericKDZ.82864
TACHYONTrojan/W32.VB-Jorik.98304.K
MalwarebytesGeneric.Trojan.Malicious.DDS
APEXMalicious
RisingWorm.Win32.Vobfus.af (CLASSIC)
YandexTrojan.GenAsa!n9vpFGRhqIs
IkarusTrojan.Patched
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACGS [Trj]
PandaW32/Vobfus.GEW.worm
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/AutoRun.VB.AVO?

Win32/AutoRun.VB.AVO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment