Malware

Win32/AutoRun.VB.ER removal guide

Malware Removal

The Win32/AutoRun.VB.ER is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.ER virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.ER?


File Info:

name: 72AB075AA413F85C10B5.mlw
path: /opt/CAPEv2/storage/binaries/30c608d4178339654d39b108a2bb79021968092293185f5d0d59b267cd72fd3c
crc32: E4050EE9
md5: 72ab075aa413f85c10b5f0ee2ce3435a
sha1: 92402cb5f06adea7a2fd1707d98eb642a96585cb
sha256: 30c608d4178339654d39b108a2bb79021968092293185f5d0d59b267cd72fd3c
sha512: 8fc29dc5032d0167561a6bc53b233ddffc61e5a6e23e68bc87b841fdba05b78bfb06defefe6f489d6e58b9b3639aaf1b558c1c8da9ca2cb23f82e1272f4ca2be
ssdeep: 768:oGgZvSerbYJLKmkwW+cBh8mvdgCXGcZDxc7mdKnI/:oHbKLHG+i8HSPZDW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C273FD63B6B35C4AD5D27EBA2B839CE60677A05E0F533651F2408B2DB638E2014D7E53
sha3_384: 11a0fc3b748c946270cd8392a23135335bee53101cf7f5aedda02ea2c185bd6626e69bb084ea201e222023030908b6d8
ep_bytes: 6808124000e8f0ffffff000000000000
timestamp: 2009-06-08 14:28:16

Version Info:

Translation: 0x0409 0x04b0

Win32/AutoRun.VB.ER also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-AYY [Wrm]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Chinky.2
FireEyeGeneric.mg.72ab075aa413f85c
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.lt
McAfeeW32/VBNA.worm.gen.c
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Basun.Win32.18782
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( f1000d031 )
K7GWTrojan ( f1000d031 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.10B1DB0920
VirITTrojan.Win32.Small.TV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ER
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Chinky-3
KasperskyWorm.Win32.Vobfus.exii
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Basun.juouou
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
AvastWin32:AutoRun-AYY [Wrm]
TencentWorm.Win32.Vobfus.pa
EmsisoftGen:Trojan.Chinky.2 (B)
BaiduWin32.Worm.AutoRun.aw
F-SecureWorm.WORM/Autorun.vzl
DrWebWin32.HLLW.Autoruner.7155
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VB.SM
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-DS
SentinelOneStatic AI – Malicious PE
JiangminWorm/Basun.abgy
VaristW32/VB.W.gen!Eldorado
AviraWORM/Autorun.vzl
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.VBNA.a
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.E
XcitiumWorm.Win32.Autorun.vzl0@1n9lsr
ArcabitTrojan.Chinky.2
ZoneAlarmWorm.Win32.Vobfus.exii
GDataGen:Trojan.Chinky.2
GoogleDetected
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Trojan.Chinky.2
Cylanceunsafe
PandaW32/Vobfus.gen.worm
TrendMicro-HouseCallWORM_VB.SM
RisingWorm.Win32.Autorun.gek (CLASSIC)
YandexTrojan.GenAsa!0qTotRoDViQ
IkarusVirus.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBNA.G!tr
Cybereasonmalicious.aa413f
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.76bf6eb8

How to remove Win32/AutoRun.VB.ER?

Win32/AutoRun.VB.ER removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment