Malware

Win32/AutoRun.VB.RL removal guide

Malware Removal

The Win32/AutoRun.VB.RL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.RL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/AutoRun.VB.RL?


File Info:

name: 45DA1CE8B1C89D46B98A.mlw
path: /opt/CAPEv2/storage/binaries/15db21017d877cc8b88948a3faba7c2819257e505b39eb8cd75b564e92463dc8
crc32: 047A7B17
md5: 45da1ce8b1c89d46b98a2160a20c181f
sha1: 7b6ae5232dfc9a4e71fd892f335414c825dc39cd
sha256: 15db21017d877cc8b88948a3faba7c2819257e505b39eb8cd75b564e92463dc8
sha512: 5db119de40d1bbfc25d090f4d8b9da99da079e180814fdec96882f688d5b0c0ecbbf91e50ccf1293ea763791dbd8e5a8750e86369b7ea2a2cbade12871d3144d
ssdeep: 1536:fuXIVTpFtGIEB70q+DQfDfDfGf+r7gRaID7fbogYAOX:VBLwIVDYFcogYAe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197C3123AB2C02707E167213D1FB3427104F4E0292D9735AA1AF79DEE6724BB4C668977
sha3_384: 0709c29e2cb1800f1b3629fc79abdf648a9f657e8d9977df383f881c1fd60cf69f3190cb46662a3f658e93c31bbc9a54
ep_bytes: 68a8124000e8f0ffffff000048000000
timestamp: 2010-07-20 10:39:50

Version Info:

Translation: 0x0409 0x04b0
ProductName: hrety43543
FileVersion: 2.63
ProductVersion: 2.63
InternalName: bxEklqAR
OriginalFilename: bxEklqAR.exe

Win32/AutoRun.VB.RL also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.VB.OEH
FireEyeGeneric.mg.45da1ce8b1c89d46
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacTrojan.VB.OEH
Cylanceunsafe
ZillyaWorm.VBNA.Win32.1501521
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 00568ebe1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 00568ebe1 )
ArcabitTrojan.VB.OEH
BitDefenderThetaGen:NN.ZevbaF.36802.hm0@aW84MCoi
VirITTrojan.Win32.Scar.KX
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.RL
APEXMalicious
TrendMicro-HouseCallWORM_VBNA.SMN
ClamAVWin.Trojan.VB-1140
KasperskyWorm.Win32.VBNA.akkf
BitDefenderTrojan.VB.OEH
NANO-AntivirusTrojan.Win32.VB.cmxsec
SUPERAntiSpywareTrojan.Agent/Gen-FraudTool
AvastWin32:AutoRun-BLX [Wrm]
TencentWorm.Win32.Vbna.fi
EmsisoftTrojan.VB.OEH (B)
BaiduWin32.Trojan.AutoRun.az
F-SecureWorm:W32/Vobfus.gen!K
DrWebWin32.HLLW.Autoruner1.13163
VIPRETrojan.VB.OEH
TrendMicroWORM_VBNA.SMN
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.gyxu
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Agent.guwj
VaristW32/Vobfus.E.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.VBNA.akkf
XcitiumTrojWare.Win32.VB.SWA@527lh3
MicrosoftWorm:Win32/Vobfus.U
ViRobotTrojan.Win32.Agent.125952.AD
ZoneAlarmWorm.Win32.VBNA.akkf
GDataWin32.Worm.VB.PSG
CynetMalicious (score: 100)
AhnLab-V3Win32/Vbna4.worm.Gen
McAfeeDownloader-CJX.gen.f
MAXmalware (ai score=86)
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.ER
ZonerTrojan.Win32.6052
RisingWorm.VobfusEx!1.99EB (CLASSIC)
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.1426687.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:AutoRun-BLX [Wrm]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/AutoRun.VB.RL?

Win32/AutoRun.VB.RL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment