Malware

Win32/AutoRun.VB.AGQ information

Malware Removal

The Win32/AutoRun.VB.AGQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.AGQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AutoRun.VB.AGQ?


File Info:

name: A728C42D0898478829EC.mlw
path: /opt/CAPEv2/storage/binaries/a347e1df013d9131c2f14621d92cafa3b8fe0729c60b771007e9682741e2e03e
crc32: CF9280BC
md5: a728c42d0898478829ecdcd5d9f8b970
sha1: 56ba8d6f4547468486c55aedfc62120327c8a4b8
sha256: a347e1df013d9131c2f14621d92cafa3b8fe0729c60b771007e9682741e2e03e
sha512: 686fe46106ea80e713d8fba6cde3b825712b2d1a15d7dfabb0bd815cb299f55b0227b38e18a15608a67fabf71e4d9c34a7a22f4ab914f3c334ff82a7202bdfce
ssdeep: 6144:FdqvgTSrMaIl/jcLijfHFEHWzXvjT85R:F8oTSrMaIqLlI/H85R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E440D26E620A03AF84684B6757DD75B60082D751790EC4BFB896B91B0B03E7F5F1A0F
sha3_384: fae8d1c44a9ca2a0614e87154298143b182c8eaedb23e7e13eaaf22fcb1d815bc2670f977391b31289dfd678a29cf74c
ep_bytes: 68c03f4000e8eeffffff000000000000
timestamp: 2011-05-30 08:53:32

Version Info:

Translation: 0x0409 0x04b0
ProductName: nIPNnYBgwGcVRPw
FileVersion: 1.00
ProductVersion: 1.00
InternalName: gRgTiOBDZb
OriginalFilename: gRgTiOBDZb.exe

Win32/AutoRun.VB.AGQ also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lr3L
MicroWorld-eScanTrojan.GenericKDZ.94562
FireEyeGeneric.mg.a728c42d08984788
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacTrojan.GenericKDZ.94562
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.c99601b4
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f45474
ArcabitTrojan.Generic.D17162
BitDefenderThetaAI:Packer.89B62C0A20
VirITTrojan.Win32.SHeur3.CBVA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AGQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1675
KasperskyWorm.Win32.Vobfus.equo
BitDefenderTrojan.GenericKDZ.94562
NANO-AntivirusTrojan.Win32.WBNA.cenndo
SUPERAntiSpywareTrojan.Agent/Gen-FraudPack
AvastWin32:VB-VBS [Wrm]
TencentWorm.Win32.Vobfus.l
TACHYONTrojan/W32.VB-VBKrypt.266240.N
EmsisoftTrojan.GenericKDZ.94562 (B)
BaiduWin32.Worm.Autorun.l
F-SecureWorm.WORM/Vobfus.CF.12
DrWebTrojan.VbCrypt.60
VIPRETrojan.GenericKDZ.94562
TrendMicroTROJ_VB.SMUS8
SophosMal/VB-XV
SentinelOneStatic AI – Malicious PE
WebrootW32.Worm.Asjb
VaristW32/Vobfus.W.gen!Eldorado
AviraWORM/Vobfus.CF.12
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.Vobfus.equo
XcitiumTrojWare.Win32.VB.AGQ@596few
MicrosoftWorm:Win32/Vobfus.CF
ViRobotDropper.Dorifel.Gen.C
ZoneAlarmWorm.Win32.Vobfus.equo
GDataTrojan.GenericKDZ.94562
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R43729
Acronissuspicious
McAfeeVBObfus.g
MAXmalware (ai score=100)
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_VB.SMUS8
RisingWorm.Win32.WBNA.q (CLASSIC)
YandexTrojan.GenAsa!Jl3AAcCdPiE
IkarusTrojan-Dropper.Win32.Dorifel
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.ADV!tr
AVGWin32:VB-VBS [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.VB.AGQ?

Win32/AutoRun.VB.AGQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment