Malware

What is “Win32/AutoRun.VB.BQC”?

Malware Removal

The Win32/AutoRun.VB.BQC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.BQC virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.spansearcher.net

How to determine Win32/AutoRun.VB.BQC?


File Info:

crc32: AC61BB16
md5: 301e8698e1321be3edc8a2a4a1005a26
name: 301E8698E1321BE3EDC8A2A4A1005A26.mlw
sha1: 8891f338d8e41b598f6dc314b3f3796c71084945
sha256: eeca773215f346d6852bb3f8186dfdd6253f1fe44c9c54eb418c024c1e2cbaea
sha512: 83793b7d8de1cfced001025ea22e667f687e623707742c75bf59f88f091bae70a72d725791128012b75947c4f501809889a5efe00e0c3c63f7a162608fc230b8
ssdeep: 1536:34c8cX2203QoLlxJcIRGWcOWPWvXArnY1ZPBizyesDNIjnZbKKk5IDDw0ZtYEvX:MQGPNJizyeACnJSI40ZtYPyD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: KAGDdWwJ
FileVersion: 1.00
OriginalFilename: KAGDdWwJ.exe
ProductName: slrKmsJdmGlc

Win32/AutoRun.VB.BQC also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.301e8698e1321be3
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.950
MalwarebytesGeneric.Trojan.Malicious.DDS
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Barys.950
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.8e1321
BitDefenderThetaGen:NN.ZevbaF.34804.im0@aevb8yli
CyrenW32/VBInject.CO.gen!Eldorado
SymantecW32.Changeup
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.pst
NANO-AntivirusTrojan.Win32.Jorik.cojaon
RisingWorm.Vobfus!1.99C3 (CLASSIC)
Ad-AwareGen:Variant.Barys.950
SophosML/PE-A + W32/Vobfus-AA
ComodoWorm.Win32.Pronny.AK@4ogvoo
F-SecureTrojan.TR/Vobfus.hydra
DrWebWin32.HLLW.Autoruner1.14951
VIPRETrojan.Win32.Vobfus.a (v)
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
EmsisoftGen:Variant.Barys.950 (B)
SentinelOneStatic AI – Malicious PE – Worm
JiangminTrojan/Vobfus.nsj
AviraTR/Vobfus.hydra
MAXmalware (ai score=86)
Antiy-AVLWorm/Win32.WBNA.gen
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmTrojan.Win32.Vobfus.pst
GDataGen:Variant.Barys.950
AhnLab-V3Trojan/Win32.Jorik.R24394
Acronissuspicious
VBA32SScope.Malware-Cryptor.VBCR.1641
TACHYONTrojan/W32.Vobfus.131072.B
ESET-NOD32a variant of Win32/AutoRun.VB.BQC
TrendMicro-HouseCallWORM_VOBFUS.SMDV
TencentWorm.Win32.Vobfus.k
YandexTrojan.GenAsa!T8iqK0VCTgM
IkarusTrojan.Win32.Vobfus
FortinetW32/VBObfus.AU!tr
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Trojan.Win32.VB.G

How to remove Win32/AutoRun.VB.BQC?

Win32/AutoRun.VB.BQC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment