Malware

Win32/AutoRun.VB.AGQ removal guide

Malware Removal

The Win32/AutoRun.VB.AGQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AGQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.AGQ?


File Info:

name: FBF88C2CF01566C27BC0.mlw
path: /opt/CAPEv2/storage/binaries/4be0432e8dba46814956ad705d51b3d018f16f4873b873fa4b5bcb478aacb2ce
crc32: 30A42C94
md5: fbf88c2cf01566c27bc09911bae113c9
sha1: 16adc255f6273ade9994a3f69726ac47f4233e7d
sha256: 4be0432e8dba46814956ad705d51b3d018f16f4873b873fa4b5bcb478aacb2ce
sha512: 1dc3ac5675da2494ed7ab03a7d7fd41dca8a0515ede4cabcfb55316f6ad810fb73935add7ad3168f0b983ba1dd3de9dd4d1508d696be20b11c5107e2e4757a44
ssdeep: 3072:SgfAlN+vh25n/kZoSUjMqXnpWAkpAmTSrMaIOYt/jo7LAtPhjjtZnfHFEoWBfGVH:SdHgTSrMaIl/jcLijfHFEHWzXvjT85R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF440D26E220A03AF94684B6757DD75B60082D751790EC4BFB896B91B0B03E7F5F1A0F
sha3_384: c59580d7d0660a4ad7f692936c6e3e64ce209f5b48411e79e197a7cde25efd9f9d3fdd47d29e76b6e7ab13e2a93a1067
ep_bytes: 68c03f4000e8eeffffff000000000000
timestamp: 2011-05-30 11:31:07

Version Info:

Translation: 0x0409 0x04b0
ProductName: XffuUHyvDeCAFwC
FileVersion: 1.00
ProductVersion: 1.00
InternalName: EyXYmsmlVa
OriginalFilename: EyXYmsmlVa.exe

Win32/AutoRun.VB.AGQ also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lr3L
MicroWorld-eScanTrojan.GenericKDZ.94562
FireEyeGeneric.mg.fbf88c2cf01566c2
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacTrojan.GenericKDZ.94562
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.94562
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.94562
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaAI:Packer.2CA07C0A20
VirITTrojan.Win32.SHeur3.CBVA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AGQ
APEXMalicious
ClamAVWin.Trojan.VB-1675
KasperskyWorm.Win32.Vobfus.equo
AlibabaWorm:Win32/Vobfus.25929f5c
NANO-AntivirusTrojan.Win32.WBNA.cenndo
ViRobotDropper.Dorifel.Gen.C
RisingWorm.Win32.WBNA.q (CLASSIC)
SophosMal/VB-XV
BaiduWin32.Worm.Autorun.l
F-SecureWorm.WORM/Vobfus.CF.12
DrWebTrojan.VbCrypt.60
ZillyaDropper.Dorifel.Win32.2744
TrendMicroTROJ_VB.SMUS8
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.94562 (B)
IkarusTrojan-Dropper.Win32.Dorifel
MAXmalware (ai score=100)
GDataTrojan.GenericKDZ.94562
WebrootW32.Malware.Gen
GoogleDetected
AviraWORM/Vobfus.CF.12
VaristW32/Vobfus.W.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.Vobfus.equo
XcitiumTrojWare.Win32.VB.AGQ@596few
ArcabitTrojan.Generic.D17162
SUPERAntiSpywareTrojan.Agent/Gen-FraudPack
ZoneAlarmWorm.Win32.Vobfus.equo
MicrosoftWorm:Win32/Vobfus.CF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R43729
Acronissuspicious
VBA32TScope.Trojan.VB
TACHYONTrojan/W32.VB-VBKrypt.266240.N
DeepInstinctMALICIOUS
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_VB.SMUS8
TencentWorm.Win32.Vobfus.l
YandexTrojan.GenAsa!Jl3AAcCdPiE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.ADV!tr
AVGWin32:VB-VBS [Wrm]
Cybereasonmalicious.5f6273
AvastWin32:VB-VBS [Wrm]

How to remove Win32/AutoRun.VB.AGQ?

Win32/AutoRun.VB.AGQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment