Worm

Worm:Win32/Autorun.AFB (file analysis)

Malware Removal

The Worm:Win32/Autorun.AFB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Autorun.AFB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Autorun.AFB?


File Info:

name: 7D22CCD6A51E9BAAF863.mlw
path: /opt/CAPEv2/storage/binaries/88ddbfae8d3a4c2c9e8b1a9a54a85c366b4ebed75023ce75364feb3dc9895c32
crc32: 3EA5F700
md5: 7d22ccd6a51e9baaf86354cdb52ef143
sha1: ce62093e38ef61a86dfb014873ce8a3a5e7c7018
sha256: 88ddbfae8d3a4c2c9e8b1a9a54a85c366b4ebed75023ce75364feb3dc9895c32
sha512: bf22f2a6f9c5f66bbdf37547a216c3cb2dd08e1ce8c4eb134644244393da77cb6e84b44cb494ad4b2d5cead4ba33eca1cad0a35ec01187d9b941ab05c71de506
ssdeep: 1536:P4xPbeTINBXFixXVG4e2JLBJ3Ue05znybzPe9j1wo7JaSU:ubeTIN5FixFG4e1ybGBwQG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BFD34F7F3F0600A5E4741578D2E3E7D22BE5784A5E17E1AAB72023685CEBE251C2CB53
sha3_384: 4dbe5229f061b07ba5f3de0a6714148a3dde52619fe8b75278e21ebbb6cd4822e90a1156b2e019ad63f0d424d5e97106
ep_bytes: 6898124000e8f0ffffff000000000000
timestamp: 2012-04-14 15:28:30

Version Info:

0: [No Data]

Worm:Win32/Autorun.AFB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vobfus.lx2G
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94628
ClamAVWin.Trojan.Vobfus-51
FireEyeGeneric.mg.7d22ccd6a51e9baa
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.dv
Cylanceunsafe
ZillyaTrojan.Vobfus.Win32.620971
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.e7b9
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.6a51e9
BaiduWin32.Worm.Autorun.v
VirITTrojan.Win32.VBCrypt.EVI
CyrenW32/Vobfus.AO.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.BWI
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.rds
BitDefenderTrojan.GenericKDZ.94628
NANO-AntivirusTrojan.Win32.Vobfus.dxrptx
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:GenMalicious-FAD [Trj]
TencentWorm.Win32.Vobfus.h
TACHYONTrojan/W32.Vobfus.135168
EmsisoftTrojan.GenericKDZ.94628 (B)
F-SecureTrojan.TR/Barys.629.jh.2
DrWebWin32.HLLW.Autoruner2.25006
VIPRETrojan.GenericKDZ.94628
TrendMicroWORM_VOBFUS.SM41
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-HZ
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.94628
JiangminTrojan.Vobfus.zrw
AviraTR/Barys.629.jh.2
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Generic.D171A4
ZoneAlarmTrojan.Win32.Vobfus.rds
MicrosoftWorm:Win32/Autorun.AFB
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R23689
BitDefenderThetaGen:NN.ZevbaF.36250.imW@aKZw9Hai
ALYacTrojan.GenericKDZ.94628
MAXmalware (ai score=80)
VBA32SScope.Malware-Cryptor.VBCR.1641
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM41
RisingWorm.VobfusEx!1.99E1 (CLASSIC)
YandexTrojan.GenAsa!AWN33uNqfj8
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:GenMalicious-FAD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Autorun.AFB?

Worm:Win32/Autorun.AFB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment