Malware

Win32/AutoRun.VB.YD malicious file

Malware Removal

The Win32/AutoRun.VB.YD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.YD virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.player1253.com
ns1.videoall.net
ns1.mediashares.org

How to determine Win32/AutoRun.VB.YD?


File Info:

crc32: F58F3BC9
md5: 2435bf6f2c02398a7b46428a93d5150e
name: 2435BF6F2C02398A7B46428A93D5150E.mlw
sha1: fa2581596481089122f19dcb97dfc53720455292
sha256: 7b56ec58c584bd4aacd17a0b758760e245983e956ed6b3c8577fea24f2526ce1
sha512: c9dcf408c5cbb51186dd4821046a6b4cd6d29969f40d2a29a1631aebf9c86b5ef71cd341831c4696f7dae324242a3211670bf8140701b2b8a5f0797141a4aa88
ssdeep: 3072:PYXaMKIuxxnM3/7eFE+S2/goM2IFNGzBkl9s0:AC/nM36q+VM2CWs9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: zKpXI562
FileVersion: 9.41
CompanyName: zKpXI562
ProductName: zKpXI3
ProductVersion: 9.41
OriginalFilename: zKpXI562.exe

Win32/AutoRun.VB.YD also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.ZGY.6
FireEyeGeneric.mg.2435bf6f2c02398a
ALYacGen:Trojan.Heur.ZGY.6
CylanceUnsafe
VIPRETrojan.Win32.Vobfus.a (v)
SangforMalware
K7AntiVirusTrojan-Downloader ( 001f4fd41 )
BitDefenderGen:Trojan.Heur.ZGY.6
K7GWTrojan-Downloader ( 001f4fd41 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.BC437D5515
CyrenW32/VB.BR.gen!Eldorado
SymantecW32.Changeup!gen10
ESET-NOD32Win32/AutoRun.VB.YD
BaiduWin32.Worm.AutoRun.cj
APEXMalicious
AvastWin32:Dropper-ESI [Drp]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.gtrd
AlibabaWorm:Win32/Jorik.3a92304a
NANO-AntivirusTrojan.Win32.Autoruner.covjws
ViRobotTrojan.Win32.A.VBKrypt.221184.F
TencentTrojan.Win32.Vobfus.b
Ad-AwareGen:Trojan.Heur.ZGY.6
SophosMal/Generic-R + Mal/Vobfus-E
ComodoMalware@#1z8nb8xnciv5f
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.44850
ZillyaTrojan.Jorik.Win32.477234
TrendMicroWORM_VOBFUS.SMIA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dt
EmsisoftGen:Trojan.Heur.ZGY.6 (B)
IkarusTrojan.Win32.VBKrypt
JiangminTrojan/VBKrypt.harr
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!E
ArcabitTrojan.Heur.ZGY.6
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AhnLab-V3Trojan/Win32.VBKrypt.R22112
ZoneAlarmTrojan.Win32.Jorik.Vobfus.gtrd
GDataGen:Trojan.Heur.ZGY.6
CynetMalicious (score: 100)
TotalDefenseWin32/Vobfus.I!generic
Acronissuspicious
McAfeeDownloader-CJX.gen.n
TACHYONTrojan/W32.VB-VBKrypt.221184.AE
VBA32SScope.Trojan.VBRA.4997
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Dropper.JUX
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingTrojan.Win32.Fednu.bjb (CLASSIC)
YandexTrojan.GenAsa!jLurHqskugk
SentinelOneStatic AI – Malicious PE – Worm
eGambitUnsafe.AI_Score_92%
FortinetW32/AutoRun.XM!worm
AVGWin32:Dropper-ESI [Drp]
Cybereasonmalicious.f2c023
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.9d4

How to remove Win32/AutoRun.VB.YD?

Win32/AutoRun.VB.YD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment