Malware

How to remove “Win32/AutoRun.VB.KM”?

Malware Removal

The Win32/AutoRun.VB.KM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.KM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.KM?


File Info:

name: BF3EE39FBF6F5D18D9C8.mlw
path: /opt/CAPEv2/storage/binaries/5a354b41ec51ab1c7a611a8fc83503220d7eac3d2b82ba28e3ee01039e9850a9
crc32: 12150B1C
md5: bf3ee39fbf6f5d18d9c8b9e30796ba44
sha1: d6905ced7dbd2a7ab3a75a6277611b40bda469fb
sha256: 5a354b41ec51ab1c7a611a8fc83503220d7eac3d2b82ba28e3ee01039e9850a9
sha512: e8c8860cf44aa8988e8aeb19a6fc6b3a338bd7cd77697487e0d53135de1ed05687ac1f40e5425b74e1b1e8125642b861f87ec9c56046a173c53346f7b8161e92
ssdeep: 768:0YgYAW0UdPZQKHyx8lHdeP/o/YfOGtDQ2LmGtN8k1:0Y9uKHyxe9eXQutMGx1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B693467DBDD24DA9C643113F3762C5FE425B298D6E0F724168082AEEBD08E1548BF953
sha3_384: 562240b6a7758e8768fac8874bb1f0c4ce8a0ef3fb4127e1fb6421ccf3216fc3c126d9ded64eb4aeadd71ad5ecaba9ea
ep_bytes: 6854124000e8f0ffffff000000000000
timestamp: 2010-01-19 13:03:52

Version Info:

Translation: 0x0409 0x04b0
CompanyName: iCMpwbLa
ProductName: iCMpwbLa
FileVersion: 2.46
ProductVersion: 2.46
InternalName: iCMpwbLa
OriginalFilename: iCMpwbLa.exe

Win32/AutoRun.VB.KM also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li7E
tehtrisGeneric.Malware
DrWebTrojan.MulDrop3.53576
MicroWorld-eScanGen:Trojan.Chinky.2
FireEyeGeneric.mg.bf3ee39fbf6f5d18
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.mm
ALYacGen:Trojan.Chinky.2
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( f1000d031 )
AlibabaWorm:Win32/Vobfus.c8c55249
K7GWTrojan ( f1000d031 )
Cybereasonmalicious.d7dbd2
BitDefenderThetaAI:Packer.7FF4887220
VirITWorm.Win32.VBNA.A
SymantecW32.Changeup!gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.KM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Vobfus-7460240-0
KasperskyWorm.Win32.VBNA.bwmh
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.AutoRun.ejdvel
AvastWin32:VB-OGL [Wrm]
TencentWorm.Win32.Vbna.zc
EmsisoftGen:Trojan.Chinky.2 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Autorun.z
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VBNA.SM
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-D
IkarusTrojan.Autorun
VaristW32/Vobfus.D.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan[AutoRun]/Win32.VB
XcitiumWorm.Win32.VBNA.~gen@1qlvkj
ArcabitTrojan.Chinky.2
ZoneAlarmWorm.Win32.VBNA.bwmh
GDataGen:Trojan.Chinky.2
GoogleDetected
AhnLab-V3Win32/Vbna4.worm.Gen
McAfeeVBObfus
MAXmalware (ai score=87)
VBA32Trojan.VB.01655
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.CP.worm
TrendMicro-HouseCallWORM_VBNA.SM
RisingTrojan.Autorun!1.DA78 (CLASSIC)
YandexWorm.VBNA.Gen
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:VB-OGL [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.KM?

Win32/AutoRun.VB.KM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment