Malware

How to remove “W32/Autorun-BFG”?

Malware Removal

The W32/Autorun-BFG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Autorun-BFG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine W32/Autorun-BFG?


File Info:

name: A1FF904880C445E8D0C6.mlw
path: /opt/CAPEv2/storage/binaries/ab707215ac9c0cc146a0657c2acb0b662354391008615bfa0608525ba35c4b69
crc32: 3A8FAB68
md5: a1ff904880c445e8d0c698cb80015e0d
sha1: 84c5c2d9984e899993669b9c539a8890dac01bad
sha256: ab707215ac9c0cc146a0657c2acb0b662354391008615bfa0608525ba35c4b69
sha512: 4e15dcff57fe8a25f3d08073264a9574af141d76486cf8c0f2471421dea9b91803f41913963aa062395368106ca830fa0e29a1920a404e340fb0006cc6efef10
ssdeep: 1536:3hkg4N/iD0Y1ObCYUXhXAXzXakcUckn98kMEW7Z:ywPG0kcUckn98kMEa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8437F6EFE05144BD60D6E313E67CA9F1EB764CE2E4F1A87251873789D36E103825A0B
sha3_384: 873bae88f91afa89bfa188474bade68b2dadb2eec39c7823e4b0483f9e306d5d7f3cc203ad8562946bbb9c06c8823381
ep_bytes: 6874124000e8eeffffff000040000000
timestamp: 2010-07-08 11:37:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: u
FileVersion: 8.13
ProductVersion: 8.13
InternalName: xrHnfWOj
OriginalFilename: xrHnfWOj.exe

W32/Autorun-BFG also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Midie.59905
FireEyeGeneric.mg.a1ff904880c445e8
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.qm
McAfeeDownloader-CJX.c
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Midie.59905
K7GWTrojan ( f1000d011 )
K7AntiVirusTrojan ( f1000d011 )
BaiduWin32.Worm.VB.as
VirITWorm.Win32.VB.12.O
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.RD
APEXMalicious
ClamAVWin.Trojan.VB-1146
KasperskyWorm.Win32.VBNA.aitt
NANO-AntivirusTrojan.Win32.Inject.covlpb
RisingWorm.VobfusEx!1.99EB (CLASSIC)
SophosW32/Autorun-BFG
F-SecureWorm:W32/Vobfus.AX
DrWebTrojan.Inject.8955
VIPREGen:Variant.Midie.59905
TrendMicroWORM_ESFURY.SMA
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Midie.59905 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
GDataGen:Variant.Midie.59905
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Dldr.Gaat.A
VaristW32/VB.BA.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.SWA@527lh3
ArcabitTrojan.Midie.DEA01
ZoneAlarmWorm.Win32.VBNA.aitt
MicrosoftWorm:Win32/Vobfus.R
CynetMalicious (score: 100)
AhnLab-V3Win32/Vbna4.worm.Gen
BitDefenderThetaAI:Packer.3BEB779A20
DeepInstinctMALICIOUS
VBA32Worm.VBNA
Cylanceunsafe
PandaW32/Vobfus.EQ
TrendMicro-HouseCallWORM_ESFURY.SMA
TencentWorm.Win32.VBNA.hew
YandexTrojan.GenAsa!9Rfy1WXFFUs
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.1443287.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:VB-PQX [Wrm]
AvastWin32:VB-PQX [Wrm]
alibabacloudTrojan.Win.UnkAgent

How to remove W32/Autorun-BFG?

W32/Autorun-BFG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment