Virus

Virus:Win32/Rungbu.C malicious file

Malware Removal

The Virus:Win32/Rungbu.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Rungbu.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executes the printer spooler process
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Virus:Win32/Rungbu.C?


File Info:

name: 93824D98A7439803271A.mlw
path: /opt/CAPEv2/storage/binaries/e8578d70af96608da51d9c13655246900ee4e8f227cd756d50fd6a369abbf8ed
crc32: BED705CE
md5: 93824d98a7439803271a706b0d9517f1
sha1: 5c47aad037636c70a0a122b73887b2efe4da17e5
sha256: e8578d70af96608da51d9c13655246900ee4e8f227cd756d50fd6a369abbf8ed
sha512: 63e6639d1381fe12856d98a7d0b8a58f0efd6a6a25245246ce44597982b920beddeb4bfc48f6a5750a872c66a51cb603cc560351c62e009b8d5b1048d0e81c48
ssdeep: 768:gSz0/XBwayCUOwV3TNZHdrPeqzEWvpbPwSMX6+w6pqZxLdeVgol9D8888888888Y:BzOCay4wV339rPjzbpLwRJ9pSdoIJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E13E1409FECBD39E8C329B988B54D035B35EA17D06AC357E0E061CE99B594398373A3
sha3_384: 6f289351e5424060009b3981afcfb0e8528bee2cde7fd22c04931499203849b5b63a9e0f4b1be30a47e58b69696d1537
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2003-08-06 18:34:23

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 11.0.5604
InternalName: WinWord
LegalCopyright: Copyright © 1983-2003 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2003
ProductVersion: 11.0.5604
Translation: 0x0000 0x04e4

Virus:Win32/Rungbu.C also known as:

BkavW32.DangerousDocCDK.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Rungbu.A
ClamAVWin.Trojan.Agent-33174
FireEyeGeneric.mg.93824d98a7439803
SkyhighBehavesLike.Win32.Rungbu.pc
McAfeeArtemis!93824D98A743
Cylanceunsafe
ZillyaVirus.VB.Win32.8
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0012046d1 )
AlibabaVirus:Win32/Rungbu.c56eab2f
K7GWVirus ( 0012046d1 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitWin32.Rungbu.A
BitDefenderThetaAI:Packer.4E9057E61C
VirITWorm.Win32.VB.APQ
SymantecW32.Dizan.D
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.NHV
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.VB.cc
BitDefenderWin32.Rungbu.A
NANO-AntivirusVirus.Win32.VB.fggxtd
SUPERAntiSpywareWorm.Agent/Gen-Silly
AvastWin32:DropperX-gen [Drp]
TencentVirus.Win32.Vb.pa
SophosW32/VB-CTQ
BaiduWin32.Trojan.Begolu.a
F-SecureMalware.W32/VB.CC
DrWebWin32.HLLW.Generic.194
VIPREWin32.Rungbu.A
TrendMicroPE_RUNGBU.C-O
Trapminemalicious.high.ml.score
EmsisoftWin32.Rungbu.A (B)
SentinelOneStatic AI – Suspicious PE
JiangminPacked.Katusha.aptx
WebrootW32.Trojan.Gen
GoogleDetected
AviraW32/VB.CC
Antiy-AVLVirus/Win32.VB.cc
KingsoftWin32.Infected.AutoInfector.a
XcitiumWorm.Win32.VB.NHV@3u28
MicrosoftVirus:Win32/Rungbu.C
ViRobotWorm.Win32.Silly.43008
ZoneAlarmVirus.Win32.VB.cc
GDataWin32.Virus.Rungflu.A
VaristW32/Worm.EAEM-2459
AhnLab-V3Win32/Rungbu
VBA32Win32.VB
ALYacWin32.Rungbu.A
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Rungbu.A.worm
TrendMicro-HouseCallPE_RUNGBU.C-O
RisingTrojan.Win32.Generic.12D7CC07 (C64:YzY0Our3Pe3g+hMl)
YandexWorm.Rungbu.B
IkarusWorm.Win32.VB
FortinetW32/VB.QJ!worm
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.037636
DeepInstinctMALICIOUS

How to remove Virus:Win32/Rungbu.C?

Virus:Win32/Rungbu.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment