Malware

What is “Win32/AutoRun.VB.AWQ”?

Malware Removal

The Win32/AutoRun.VB.AWQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AWQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.AWQ?


File Info:

name: FC5B3F166C96C5B44BB2.mlw
path: /opt/CAPEv2/storage/binaries/f59cb501e9569c0a9337b53078882e266e4cc6a63e07779e64bfe8c6a4d2db68
crc32: E29E443D
md5: fc5b3f166c96c5b44bb210208e9723d9
sha1: d06c96fcc2e22a775d4d971d9065979829d57778
sha256: f59cb501e9569c0a9337b53078882e266e4cc6a63e07779e64bfe8c6a4d2db68
sha512: f590c224165472357b0eef7f5d67c2bac68cfc5aa83b97145127eb14793af473f6ef56a88ff0e231e7c75d03801e7b2362b0e44779254ec895a587218b384b89
ssdeep: 6144:tgJDdsPCDMzJu749QepWyBLTURx44IhR0:tuwzJuZeseLTUR6m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB547426A3D0F73DE861C6F828554650986AAD3318E1EC0BF6D19B1A77B1E57F220373
sha3_384: deecdf6a09ab0e10ad12521aaffa726855d6768403fa91577d958e489697ca31e3c8c3b01953467cf96830ad7163f9bb
ep_bytes: 6848524000e8f0ffffff000060000000
timestamp: 2012-06-05 18:56:33

Version Info:

Translation: 0x0409 0x04b0
Comments: gairfish viaggiato Plumagery
CompanyName: nonprojectively expensefully Modificatory
FileDescription: Protephemeroid
LegalCopyright: Dyspepsy
LegalTrademarks: Damagingly Katti
ProductName: chris
FileVersion: 25.00
ProductVersion: 25.00
InternalName: enzpxgfumb
OriginalFilename: enzpxgfumb.exe

Win32/AutoRun.VB.AWQ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.14537
FireEyeGeneric.mg.fc5b3f166c96c5b4
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Symmi.14537
Cylanceunsafe
ZillyaTrojan.Jorik.Win32.1088312
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Jorik.6754a0a2
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.66c96c
ArcabitTrojan.Symmi.D38C9
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.SHeur4.AHFV
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup!gen18
ESET-NOD32Win32/AutoRun.VB.AWQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.eryt
BitDefenderGen:Variant.Symmi.14537
NANO-AntivirusTrojan.Win32.Jorik.covkub
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ADGX [Trj]
RisingWorm.Autorun!1.ACE1 (CLASSIC)
TACHYONTrojan/W32.Jorik.282624
SophosMal/SillyFDC-W
F-SecureBackdoor.BDS/Backdoor.Gen7
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Symmi.14537
TrendMicroWORM_VOBFUS.SMED
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Suspicious PE
AviraBDS/Backdoor.Gen7
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
MicrosoftWorm:Win32/Vobfus.gen!R
ViRobotWorm.Win32.A.WBNA.282624.NV
ZoneAlarmTrojan.Win32.Jorik.Vobfus.eryt
GDataGen:Variant.Symmi.14537
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R27224
McAfeeVBObfus.ek
MAXmalware (ai score=87)
VBA32BScope.Trojan.Diple
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMED
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!ttGgAq7YRCs
IkarusTrojan.Win32.Meredrop
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36318.rm0@aestTzli
AVGWin32:VB-ADGX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.AWQ?

Win32/AutoRun.VB.AWQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment