Malware

Should I remove “Win32/AutoRun.VB.VN”?

Malware Removal

The Win32/AutoRun.VB.VN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.VN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/AutoRun.VB.VN?


File Info:

name: 28923C25D8DEC04FACD1.mlw
path: /opt/CAPEv2/storage/binaries/406c32d693b73f2be3e280294c7a15a550d72c33109e6d03367f366c0d99c555
crc32: 0374D8C4
md5: 28923c25d8dec04facd17b7c464afc5c
sha1: cbe66a3bfdbbefb5923f993d061a4bd8201b1983
sha256: 406c32d693b73f2be3e280294c7a15a550d72c33109e6d03367f366c0d99c555
sha512: e92b844d454b6f2d2f34575f4d907c3373843c246530cb74733d0694f62224e07b2937cfbc59dd84e5fe7acfb9f7bd42bf7581c6223e9e0a25abebb926eb6284
ssdeep: 1536:BwxywdnXcVYvYdYOYGYCVVB+fuIgb6Upud8/QkL0jNiQDSWDhv3/Q4VDUtd7fIs/:WMKXc5A5SWDhv3/Q4VDUtd7fIs/jOW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1966468E0F1C16203E8290EFA4B4B65FA4E5AF2FC68513441359F0D292F099D9FB647B9
sha3_384: 728a781276052a09d5f453babf7749db556723a1ae43c395d5dd93f2c0230aab8265c466a405ebc2283408b2ebba4cae
ep_bytes: 68a8114000e8eeffffff000000000000
timestamp: 2010-10-25 08:01:25

Version Info:

Translation: 0x0409 0x04b0
ProductName: jjnUG1
FileVersion: 2.1467
ProductVersion:

Win32/AutoRun.VB.VN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lt4u
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.34218
MicroWorld-eScanTrojan.GenericKDZ.86337
FireEyeGeneric.mg.28923c25d8dec04f
CAT-QuickHealTrojan.VBCrypt.MF.4008
SkyhighBehavesLike.Win32.VBObfus.fm
McAfeeDownloader-CJX.gen.j
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.VBKrypt.Win32.14255
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 001f4fd41 )
AlibabaWorm:Win32/Vobfus.66fcfad8
K7GWTrojan ( 001f4fd41 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.4A59D06B20
VirITTrojan.Win32.VBKrypt.UVD
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.VN
APEXMalicious
TrendMicro-HouseCallWORM_VBNA.SMCE
ClamAVWin.Trojan.VB-1317
KasperskyWorm.Win32.WBNA.ipa
BitDefenderTrojan.GenericKDZ.86337
NANO-AntivirusTrojan.Win32.WBNA.dwuoev
AvastWin32:AutoRun-BPR [Wrm]
TencentWorm.Win32.Wbna .16000410
SophosMal/SillyFDC-D
GoogleDetected
F-SecureWorm:W32/Vobfus.AX
BaiduWin32.Worm.VB.al
VIPRETrojan.GenericKDZ.86337
TrendMicroWORM_VBNA.SMCE
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.86337 (B)
IkarusWorm.Win32.Vobfus
GDataTrojan.GenericKDZ.86337
JiangminTrojan/VBKrypt.hbyt
WebrootW32.Malware.Gen
VaristW32/Vobfus.K.gen!Eldorado
AviraWORM/Vobfus.bde
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Autorun.VV@26y5pr
ArcabitTrojan.Generic.D15141
ViRobotWorm.Win32.Vobfus.311296
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftWorm:Win32/Vobfus.gen!D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R4216
ALYacTrojan.GenericKDZ.86337
MAXmalware (ai score=99)
VBA32Trojan.VBRA.04692
Cylanceunsafe
PandaW32/Vobfus.FH
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!pWRgsXNPdr0
SentinelOneStatic AI – Malicious PE
FortinetW32/AutoRun.VBB!tr
AVGWin32:AutoRun-BPR [Wrm]
Cybereasonmalicious.bfdbbe
DeepInstinctMALICIOUS

How to remove Win32/AutoRun.VB.VN?

Win32/AutoRun.VB.VN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment