Malware

Should I remove “Win32/AutoRun.VB.GC”?

Malware Removal

The Win32/AutoRun.VB.GC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.VB.GC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/AutoRun.VB.GC?


File Info:

crc32: 662FFFF6
md5: 06bad122fb459a3c2ca79df06a30e2b3
name: 06BAD122FB459A3C2CA79DF06A30E2B3.mlw
sha1: 73ccfd9933a55c92678e5d124a1af7c8ddf7de76
sha256: 2b530553421782ff9ce8f81474695ea3a6b81f5f44249621e3c54c51742911d9
sha512: 98d4e93b154e8a2a6c98787508b8529cc9c90e320c6b90cab23e40a5e432eb20537f024d2e8033ba0e5fd9df4609290070cdbe8ca521d4a7f7ef2309706b42f4
ssdeep: 768:nVMoUHXFHq9scwbHP2jI6svfjGq9tWKtGErwSKVIJuYO41HmzHp7Z6T1os:nkHFq9scwbV6snjG1KtGErPn71H4YTys
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: EXPL0RER
FileVersion: 192.168.0001
CompanyName: x5faex8f6fx4e2dx56fd
ProductName: winlog
ProductVersion: 192.168.0001
OriginalFilename: EXPL0RER.exe

Win32/AutoRun.VB.GC also known as:

K7AntiVirusHacktool ( 005286401 )
Elasticmalicious (high confidence)
DrWebWorm.Siggen.95
ClamAVWin.Worm.Lamer-6726356-0
CAT-QuickHealWorm.AutorunVMF.S21201167
McAfeeW32/Autorun.worm.ie
CylanceUnsafe
ZillyaWorm.VB.Win32.466
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWHacktool ( 005286401 )
Cybereasonmalicious.2fb459
BaiduWin32.Virus.Hehe.a
CyrenW32/Worm.JLLC-3392
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.VB.GC
APEXMalicious
AvastWin32:AutoRun-JW
CynetMalicious (score: 100)
KasperskyVirus.Win32.Lamer.cw
BitDefenderGen:Trojan.Malware.em0@aa2Kuycb
NANO-AntivirusTrojan.Win32.VB.jzde
ViRobotWorm.Win32.VB.69632.U
MicroWorld-eScanGen:Trojan.Malware.em0@aa2Kuycb
TencentTrojan.Win32.VB.bex
Ad-AwareGen:Trojan.Malware.em0@aa2Kuycb
SophosML/PE-A + Mal/Generic-E
ComodoWorm.Win32.Agent.~MA@1346u
BitDefenderThetaAI:Packer.51E701591C
TrendMicroPE_LAMER.K-O
McAfee-GW-EditionW32/Autorun.worm.ie
FireEyeGeneric.mg.06bad122fb459a3c
EmsisoftGen:Trojan.Malware.em0@aa2Kuycb (B)
SentinelOneStatic AI – Malicious PE
JiangminVirus.Win32.Lamer.a
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.B13
KingsoftWin32.Infected.AutoInfector.a.(kcloud)
MicrosoftWorm:Win32/Autorun.AER
ArcabitTrojan.Malware.E3E5AA
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Trojan.Malware.em0@aa2Kuycb
TACHYONTrojan/W32.VB-Agent.69632.NO
AhnLab-V3Trojan/Win32.Agent.R148495
VBA32Virus.Lamer.26219
MAXmalware (ai score=85)
MalwarebytesWorm.AutoRun
PandaW32/Autorun.ZZ.worm
TrendMicro-HouseCallPE_LAMER.K-O
RisingVirus.Lamer!1.9B79 (CLASSIC)
YandexTrojan.GenAsa!JNeVVLDZ8Jo
IkarusWorm.Win32.AutoRun
MaxSecureVirus.W32.Lamer.CW
FortinetW32/Lamer.CW!tr
AVGWin32:AutoRun-JW
Qihoo-360Win32/Virus.VBViking.HwMAqPEA

How to remove Win32/AutoRun.VB.GC?

Win32/AutoRun.VB.GC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment