Malware

How to remove “Win32/AutoRun.VB.BQA”?

Malware Removal

The Win32/AutoRun.VB.BQA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.BQA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.BQA?


File Info:

name: E2A8A64215CDA08C5F9F.mlw
path: /opt/CAPEv2/storage/binaries/a415ad6df29a470ca73c8d8e2657affec427f0ec8c9c977a934b8ca28d3aa848
crc32: FE2634DD
md5: e2a8a64215cda08c5f9f2362b0bf0520
sha1: af4cf995578516d73fdd4c74273f069113c59466
sha256: a415ad6df29a470ca73c8d8e2657affec427f0ec8c9c977a934b8ca28d3aa848
sha512: bb703d1e01c3a81d042efc3bde2a59a3d7598af98c2f6dea6eec5f46009b9b22d6eda87ec6b4c41bba96b9e81a4ab67b3ffaeaf4a9c0304fac26d46a2331f4df
ssdeep: 6144:9Cbc0f7XP+g3AGJpWVzu7RHeEgRK/fObT/bGiJKv6R7MkZ4lUr8W9HuOGKqvsMMJ:4w27/XvLWputeEgRK/fObT/bGiJlMkZp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1642A12EA11702BE45285F05A6943B77A3D2CB62750AC0B7781FF1A56B06C3FAB435F
sha3_384: e70cdd5cb79cbfe2beb9bede2a4e2ca112fd7969b32d868cde6fdbc674871a324f65ed87d121be768a09cafa401a7122
ep_bytes: 68e4394000e8f0ffffff000000000000
timestamp: 2011-11-19 20:48:17

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:
Translation: 0x0409 0x04b0

Win32/AutoRun.VB.BQA also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lrSX
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.77
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.e2a8a64215cda08c
CAT-QuickHealTrojan.VBCryptVMF.S26740004
ALYacGen:Variant.VBInject.11
Cylanceunsafe
ZillyaTrojan.Jorik.Win32.1009143
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Jorik.0b0a7ea8
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36196.tm0@a8H0Jcgi
VirITTrojan.Win32.Diple.DBGO
CyrenW32/Vobfus.Z.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.BQA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.gtqo
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.Autoruner1.hlurbp
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ZUK [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.Jorik.319488.B
SophosW32/SillyFDC-GI
F-SecureTrojan.TR/Vobfus.3194881
BaiduWin32.Worm.Autorun.l
VIPREGen:Variant.VBInject.11
TrendMicroWORM_VOBFUS.SM4
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fh
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.VBInject.11 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Diple.dmae
AviraTR/Vobfus.3194881
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBInject.11
ViRobotTrojan.Win32.A.Diple.319488.B
ZoneAlarmTrojan.Win32.Jorik.Vobfus.gtqo
GDataGen:Variant.VBInject.11
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R16322
McAfeeVBObfus.by
MAXmalware (ai score=82)
VBA32BScope.Trojan.Diple
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaGeneric Malware
ZonerTrojan.Win32.86751
TrendMicro-HouseCallWORM_VOBFUS.SM4
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!quZavOW0dAY
IkarusTrojan.Vobfus
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-ZUK [Trj]
Cybereasonmalicious.215cda
DeepInstinctMALICIOUS

How to remove Win32/AutoRun.VB.BQA?

Win32/AutoRun.VB.BQA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment