Is (unnamed file) safe?
Strong tier-1 consensus across 37 engines identifies this as a VBS/Autorun worm.
29 of 37 engines flag the file, with 10 tier-1 engines converging on the autorun worm family. No signing, sandbox, or benign history offsets the detection.
f7658dce18999a70da…dc294b49b7c42cRecommended next actions
Before opening
Do not open it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already opened it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
29 of 37 engines flag the file, with 10 tier-1 engines converging on the autorun worm family. No signing, sandbox, or benign history offsets the detection.
The engine results show a clear tier-1 consensus on the autorun worm family, corroborated by multiple independent high-trust vendors. The file is rare and old with no prior benign submissions, and no code-signing or runtime data exists to contradict the detections. Low-trust detections are present but unnecessary given the tier-1 agreement.
What We Detected
10 tier-1 engines and 19 additional engines label the sample as a VBS autorun worm. Common family strings include VBS/Autorun.I, Worm.VBS.Autorun.i, and VBS:AutoRun-G.
Threat Behavior
Autorun worms typically spread via removable media and network shares by exploiting Windows autorun features. No sandbox execution data is available for this sample.
What To Do Now
Do not execute the file. Keep endpoint protection enabled and scan any media that may have been in contact with the sample.
- Strong tier-1 family consensus on autorun worm
- Rare file with zero prior benign submissions
Treat the file as malicious and block or remove it; maintain current security tooling.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete29 of 37 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Threat context
How worms spread
A worm copies itself from one computer to the next — across your network, through shared drives, or on USB sticks — without you doing anything. One infected machine can quickly reach every device around it.
Bottom line:A single infected machine can rapidly compromise every device it can reach.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 29 / 37engines flagged
- 0sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
29 of 37 antivirus engines flagged the file, including AntiVir and Authentium.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at
Detection sources at a glance
Category: worm
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
29 of 37 engines flagged this file
View all 37 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.
Fingerprint and provenance
- File name
- (unnamed file)
- Format
- unknown
- Code signing
- Not applicable to this file type
- Size
- 402.2 KB
- Last analyzed
- Sep 6, 2026, 10:52 AM UTC
f7658dce18999a70da5ebacd1abec048694daaecec7e3153d2dc294b49b7c42cSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is this file a virus?
What is this file?
How many antivirus engines detected this file?
What should I do if I already opened this file?
How do I remove this file?
What kind of malware is this file?
What is the SHA-256 hash of this file?
How up to date is this analysis of this file?
Community
Member reviews and reports for this exact file hash.