Virus

Virus:Win32/Rungbu.C (file analysis)

Malware Removal

The Virus:Win32/Rungbu.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Rungbu.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executes the printer spooler process
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Virus:Win32/Rungbu.C?


File Info:

name: DCF3196558DD81AC7CC6.mlw
path: /opt/CAPEv2/storage/binaries/2ea25da9ffbe780f127111044e5b33d38d09277a6c190e6e43be6b696b3103ce
crc32: 712DB732
md5: dcf3196558dd81ac7cc601fefb26c70f
sha1: b02761c2d3d9be91063c20143211fdd696869e09
sha256: 2ea25da9ffbe780f127111044e5b33d38d09277a6c190e6e43be6b696b3103ce
sha512: e491e55c81037a7e8a7d8079782bc611ae6f11b9790d9091d475f39009964e6ef9d396729a3cc7824296596e13f692a9d91d744d4c3449a7ea56b70f068ef89b
ssdeep: 768:gSz0/XBwayCUOwV3TNZHdrPeqzEWvpbPwSMX6+w6pqZxLdeVgol9D88888888882:BzOCay4wV339rPjzbpLwRJ9pSdoID
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11513E1409FECBD39E8C3297988B54D135B35EA17D06AC357E0E061CE99B594398373A3
sha3_384: 5a22c618084757271239fe46a4c2959012843a8af1dd4cd1a2c990f2e226ca0cebff32d3453e3b70a400592f3db67442
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2003-08-06 18:34:23

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 11.0.5604
InternalName: WinWord
LegalCopyright: Copyright © 1983-2003 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2003
ProductVersion: 11.0.5604
Translation: 0x0000 0x04e4

Virus:Win32/Rungbu.C also known as:

BkavW32.DangerousDocCDK.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Rungbu.A
ClamAVWin.Trojan.Agent-33174
FireEyeGeneric.mg.dcf3196558dd81ac
SkyhighBehavesLike.Win32.Rungbu.pc
McAfeeW32/Rungbu
Cylanceunsafe
ZillyaVirus.VB.Win32.8
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0012046d1 )
K7GWVirus ( 0012046d1 )
Cybereasonmalicious.2d3d9b
BaiduWin32.Trojan.Begolu.a
VirITWorm.Win32.VB.APQ
SymantecW32.Dizan.D
ESET-NOD32Win32/VB.NHV
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.VB.cc
BitDefenderWin32.Rungbu.A
NANO-AntivirusVirus.Win32.VB.fggxtd
SUPERAntiSpywareWorm.Agent/Gen-Silly
AvastWin32:DropperX-gen [Drp]
TencentVirus.Win32.Vb.pa
SophosW32/VB-CTQ
F-SecureMalware.W32/VB.CC
DrWebWin32.HLLW.Generic.194
VIPREWin32.Rungbu.A
TrendMicroPE_RUNGBU.C-O
EmsisoftWin32.Rungbu.A (B)
IkarusWorm.Win32.VB
GDataWin32.Virus.Rungflu.A
JiangminPacked.Katusha.aptx
WebrootW32.Trojan.Gen
GoogleDetected
AviraW32/VB.CC
Antiy-AVLVirus/Win32.VB.cc
XcitiumWorm.Win32.VB.NHV@3u28
ArcabitWin32.Rungbu.A
ViRobotWorm.Win32.Silly.43008
ZoneAlarmVirus.Win32.VB.cc
MicrosoftVirus:Win32/Rungbu.C
VaristW32/Worm.EAEM-2459
AhnLab-V3Win32/Rungbu
VBA32Win32.VB
ALYacWin32.Rungbu.A
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Rungbu.A.worm
TrendMicro-HouseCallPE_RUNGBU.C-O
RisingTrojan.Win32.Generic.12D7CC07 (C64:YzY0Our3Pe3g+hMl)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7175209.susgen
FortinetW32/VB.QJ!worm
BitDefenderThetaAI:Packer.4E9057E61C
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Rungbu.C?

Virus:Win32/Rungbu.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment