Malware

Win32/AutoRun.VB.CG (file analysis)

Malware Removal

The Win32/AutoRun.VB.CG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.CG virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/AutoRun.VB.CG?


File Info:

crc32: 6622C77E
md5: 08500989be99bc30e9f4eb60b2f336c0
name: PSeInt-Portable.exe
sha1: d527c5c31b2694c3cd2bb49b4f7411e7ed83bdf2
sha256: 4dd91c0f4ab136f23b44e8b833813c539104e7d243bded019cf74139d0e4929f
sha512: 935e5781f022aaeed34d5def8360bb694de5390b2fcc359daa40f4ef7929cd5d09cdaf23c7d0e3853751c1050ca99dfabc8d18c4a4007d4e8b0d428901cabb55
ssdeep: 49152:WJL51zkMx7OmG5GgrtrOCzNOnq6bZYlurcNXryW5463HVBdjfoHgNKjNHSiBbTA1:o7MdzQq6ZYl5463HV/jfEpNHSiJ06O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/AutoRun.VB.CG also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.3366966
FireEyeTrojan.GenericKD.3366966
Qihoo-360Win32/Trojan.b6a
ALYacTrojan.GenericKD.3366966
CylanceUnsafe
AegisLabTrojan.Win32.AutoRun.4!c
K7AntiVirusP2PWorm ( 0055e3e51 )
BitDefenderTrojan.GenericKD.3366966
K7GWP2PWorm ( 0055e3e51 )
Cybereasonmalicious.9be99b
CyrenW32/Trojan.AYRG-8494
SymantecTrojan.ADH.2
ESET-NOD32Win32/AutoRun.VB.CG
GDataTrojan.GenericKD.3366966
KasperskyTrojan.Win32.AutoRun.bp
AlibabaWorm:Win32/Generic.c400097a
NANO-AntivirusTrojan.Win32.AutoRun.chthzo
TencentWin32.Trojan.Autorun.Eya
Ad-AwareTrojan.GenericKD.3366966
SophosMal/Generic-S
F-SecureTrojan.TR/Autorun.bp.2
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
EmsisoftTrojan.GenericKD.3366966 (B)
WebrootW32.AutoRun
AviraTR/Autorun.3771493bhv
ArcabitTrojan.Generic.D336036
ZoneAlarmTrojan.Win32.AutoRun.bp
MicrosoftTrojan:Win32/Occamy.C
McAfeeArtemis!08500989BE99
MAXmalware (ai score=80)
RisingWorm.Autorun!8.50 (CLOUD)
YandexTrojan.AutoRun!czS7HqiGJDk
IkarusTrojan.Autorun
FortinetW32/Autorun.BP!tr
AVGINF:AutoRun-DL [Wrm]
AvastINF:AutoRun-DL [Wrm]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/AutoRun.VB.CG?

Win32/AutoRun.VB.CG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment