Malware

How to remove “Win32/AutoRun.VB.AZK”?

Malware Removal

The Win32/AutoRun.VB.AZK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AZK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.AZK?


File Info:

name: 3632ED107089BD828273.mlw
path: /opt/CAPEv2/storage/binaries/81c9bbd9119443d22ab9bc380bac32dd55c760054f138d0adbb50ba110da3fd1
crc32: 9821F878
md5: 3632ed107089bd828273de03a20a88f2
sha1: 4e3e44b3b5310f9239e97d7ce4fd74e500263374
sha256: 81c9bbd9119443d22ab9bc380bac32dd55c760054f138d0adbb50ba110da3fd1
sha512: 56efdf72356d61e126dff56b2e7398f64cd4c98b611e131257fa6e18b0df8c4d003a66e96448ebb0f0b09d0466ec9a53fcd1a4f5505425e1de7d31b3b7aad30b
ssdeep: 6144:x+AhyrimEU/EztV++Jbtd4lfn8hFXbTom85FMnH:xN0rimr/EztV++JZd4lfnSTo7F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119440C26E620A03AF98784F6B069E39A340C2D7507D1EC07B7856B95B0B42D7F5F261F
sha3_384: ea041cc9d350348a1e3135d43fd6687bcfedf0cde29d6adcd790ddf9ad4f3bcdeee28736b45acf169b5b90f5458bd963
ep_bytes: 68d03e4000e8f0ffffff000000000000
timestamp: 2011-06-01 02:44:08

Version Info:

Translation: 0x0409 0x04b0
ProductName: IiwIDbWxj
FileVersion: 1.00
ProductVersion: 1.00
InternalName: SnZipJZKxyeozk
OriginalFilename: SnZipJZKxyeozk.exe

Win32/AutoRun.VB.AZK also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.g
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Chinky.6
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.SHeur3.CCGQ
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.AZK
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.apc
BitDefenderGen:Variant.Chinky.6
NANO-AntivirusTrojan.Win32.WBNA.eihzwi
MicroWorld-eScanGen:Variant.Chinky.6
AvastWin32:VB-UKD [Trj]
TencentWorm.Win32.WBNA.hn
TACHYONTrojan/W32.VB-VBKrypt.258048.J
SophosMal/VB-XV
F-SecureWorm.WORM/Vobfus.CF.27
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Chinky.6
TrendMicroWORM_VBNA.SMED
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.3632ed107089bd82
EmsisoftGen:Variant.Chinky.6 (B)
IkarusGen.Variant.Chinky
GoogleDetected
AviraWORM/Vobfus.CF.27
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.998
XcitiumWorm.Win32.Vobfus.E@3unn0h
MicrosoftWorm:Win32/Vobfus.CF
ZoneAlarmWorm.Win32.WBNA.apc
GDataGen:Variant.Chinky.6
VaristW32/Vobfus.W.gen!Eldorado
AhnLab-V3Trojan/Win32.VBKrypt.R15972
Acronissuspicious
BitDefenderThetaAI:Packer.48CE1FE120
ALYacGen:Variant.Chinky.6
MAXmalware (ai score=88)
VBA32Malware-Cryptor.VB.gen
Cylanceunsafe
PandaW32/Vobfus.GEP
TrendMicro-HouseCallWORM_VBNA.SMED
YandexTrojan.GenAsa!bt6veHZZNC8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.ADV!tr
AVGWin32:VB-UKD [Trj]
Cybereasonmalicious.07089b
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/AutoRun.VB.AZK?

Win32/AutoRun.VB.AZK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment