Malware

Win32/AutoRun.VB.YJ removal instruction

Malware Removal

The Win32/AutoRun.VB.YJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.YJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.YJ?


File Info:

name: 796538A3AFB70D07C35E.mlw
path: /opt/CAPEv2/storage/binaries/13b7503f51d67073b6acc7031dfdbd86d0705c90aff82fdbe0031d09b6ec0ec9
crc32: 9F7FB63D
md5: 796538a3afb70d07c35eed9a7f39002d
sha1: 13e1cbc401e9c21c7736a315a26c48fd7d400ea1
sha256: 13b7503f51d67073b6acc7031dfdbd86d0705c90aff82fdbe0031d09b6ec0ec9
sha512: 3073da84f9ebd4efb3d63546acde856f3d0b672814d48f5094cdecede78083d87b221bea7c126d7ecc919146f923843a44c0a120574857188dcea09d556ff871
ssdeep: 3072:GgywcJ3RT3qLSbM1vLEV+NODgcA+3rW4EhN3gTjk:jjcvpuOUdkrWdn3F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A440C74A7A720C0D82698797183B3DB883A7160BA331496DB122759EE15F80D73DDBF
sha3_384: 1591efe44ea274bb9c714f6ffd3bc766c161d96bbe073ec928546cf18c0ebc8a58c20d99db23d01d98f98c145aa7d735
ep_bytes: 682c124000e8f0ffffff000000000000
timestamp: 2011-01-09 04:56:40

Version Info:

Translation: 0x0409 0x04b0
CompanyName: hFlWb398
ProductName: hFlWb4397
FileVersion: 3.62
ProductVersion: 3.62
InternalName: hFlWb398
OriginalFilename: hFlWb398.exe

Win32/AutoRun.VB.YJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.42213
MicroWorld-eScanGen:Variant.VBKrypt.23
ClamAVWin.Worm.Vobfus-9784373-0
FireEyeGeneric.mg.796538a3afb70d07
CAT-QuickHealWorm.WbnaMF.S27266075
SkyhighBehavesLike.Win32.Downloader.dm
ALYacGen:Variant.VBKrypt.23
ZillyaWorm.WBNAGen.Win32.6
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
AlibabaWorm:Win32/Vobfus.5f3b6b2b
K7GWTrojan-Downloader ( 001ff72a1 )
Cybereasonmalicious.401e9c
ArcabitTrojan.VBKrypt.23
BitDefenderThetaAI:Packer.2FFC863E20
VirITTrojan.Win32.VBKrypt.ASUC
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.YJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.WBNA.crkzlq
AvastWin32:VB-QRX [Trj]
TencentWin32.Worm.Wbna.Jjgl
EmsisoftGen:Variant.VBKrypt.23 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.VB.qd
VIPREGen:Variant.VBKrypt.23
TrendMicroWORM_VBNA.SMTB
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-I
SentinelOneStatic AI – Malicious PE
JiangminTrojan/VBKrypt.hdxv
WebrootW32.Malware.Downloader
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.WBNA.ipa
XcitiumTrojWare.Win32.VB.Y@2n9y3l
MicrosoftTrojanDownloader:Win32/Agent
ViRobotTrojan.Win32.A.VBKrypt.258048.CH
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.VBKrypt.23
VaristW32/VB.BR.gen!Eldorado
AhnLab-V3Trojan/Win32.VBKrypt.R2546
McAfeeDownloader-CJX.gen.o
MAXmalware (ai score=99)
VBA32Trojan.VBRA.06010
Cylanceunsafe
PandaW32/Autorun.JUV.worm
TrendMicro-HouseCallWORM_VBNA.SMTB
RisingWorm.Autorun!1.D163 (CLASSIC)
YandexTrojan.GenAsa!kzGc1bM1Y3c
IkarusTrojan.Win32.VBKrypt
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-QRX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.YJ?

Win32/AutoRun.VB.YJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment