Virus

Virus:Win32/Rungbu.C removal instruction

Malware Removal

The Virus:Win32/Rungbu.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Rungbu.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executes the printer spooler process
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Virus:Win32/Rungbu.C?


File Info:

name: E74059515903225F55ED.mlw
path: /opt/CAPEv2/storage/binaries/761381eb6da7b62b9d5336e53a5b7a4270b572266453a2ede0f7e5c5b1242ae4
crc32: 52FDBEB9
md5: e74059515903225f55eddd97796d9de9
sha1: 6408580fb77f0d0f1f9980fd2af0bbb1620b2370
sha256: 761381eb6da7b62b9d5336e53a5b7a4270b572266453a2ede0f7e5c5b1242ae4
sha512: ca37c85dfda9023378626166e8f09e21fb4f72843be4f8f025b163a056c0f024c77c69fca67c378b1fc325dcbd34df4f9ec1bbfbc166e9d6bae7a237a417aa51
ssdeep: 768:gSz0/XBwayCUOwV3TNZHdrPeqzEWvpbPwSMX6+w6pqZxLdeVgol9D8888888888+:BzOCay4wV339rPjzbpLwRJ9pSdoIP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19013E1409FECBD39E8C3297988B54D135B35EA17D06AC357A0E061CE99B594398373A3
sha3_384: 2598bac0879afddece79ebf62b8d6ddd8c9c28fc03f0bc9e1b269c34a22e899e59a0e79257e9474c0ad2928e8d329d6c
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2003-08-06 18:34:23

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 11.0.5604
InternalName: WinWord
LegalCopyright: Copyright © 1983-2003 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2003
ProductVersion: 11.0.5604
Translation: 0x0000 0x04e4

Virus:Win32/Rungbu.C also known as:

BkavW32.DangerousDocCDK.PE
LionicVirus.Win32.VB.lfFr
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Rungbu.A
FireEyeGeneric.mg.e74059515903225f
SkyhighBehavesLike.Win32.Rungbu.pc
McAfeeArtemis!E74059515903
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Rungbu.A
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0012046d1 )
AlibabaVirus:Win32/Rungbu.972e383f
K7GWVirus ( 0012046d1 )
Cybereasonmalicious.159032
BaiduWin32.Trojan.Begolu.a
VirITWorm.Win32.VB.APQ
SymantecW32.Dizan.D
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.NHV
APEXMalicious
TrendMicro-HouseCallPE_RUNGBU.C-O
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.Agent-33174
KasperskyVirus.Win32.VB.cc
BitDefenderWin32.Rungbu.A
NANO-AntivirusVirus.Win32.VB.fggxtd
SUPERAntiSpywareWorm.Agent/Gen-Silly
TencentVirus.Win32.Vb.pa
SophosW32/VB-CTQ
F-SecureMalware.W32/VB.CC
DrWebWin32.HLLW.Generic.194
ZillyaVirus.VB.Win32.8
TrendMicroPE_RUNGBU.C-O
Trapminemalicious.high.ml.score
EmsisoftWin32.Rungbu.A (B)
IkarusWorm.Win32.VB
MAXmalware (ai score=100)
JiangminPacked.Katusha.aptx
GoogleDetected
AviraW32/VB.CC
VaristW32/Worm.EAEM-2459
Antiy-AVLVirus/Win32.VB.cc
KingsoftWin32.Infected.AutoInfector.a
MicrosoftVirus:Win32/Rungbu.C
XcitiumWorm.Win32.VB.NHV@3u28
ArcabitWin32.Rungbu.A
ViRobotWorm.Win32.Silly.43008
ZoneAlarmVirus.Win32.VB.cc
GDataWin32.Virus.Rungflu.A
CynetMalicious (score: 100)
AhnLab-V3Win32/Rungbu
VBA32Win32.VB
ALYacWin32.Rungbu.A
Cylanceunsafe
PandaW32/Rungbu.A.worm
RisingDropper.Vbex!1.9A13 (CLOUD)
YandexWorm.Rungbu.B
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7175209.susgen
FortinetW32/VB.QJ!worm
BitDefenderThetaAI:Packer.4E9057E61C
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm

How to remove Virus:Win32/Rungbu.C?

Virus:Win32/Rungbu.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment