Backdoor

Backdoor.VB.Agent.ABT (B) (file analysis)

Malware Removal

The Backdoor.VB.Agent.ABT (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.VB.Agent.ABT (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Backdoor.VB.Agent.ABT (B)?


File Info:

name: 4B49F4D299FDAAF20D43.mlw
path: /opt/CAPEv2/storage/binaries/b7058df5c98bf1180463b717629972233e7cfebf5bc33f279e62edd69cd81cbd
crc32: 8F908C91
md5: 4b49f4d299fdaaf20d4340695ed02973
sha1: b10d6823115fd3259b066fceddb8b2e1246ca962
sha256: b7058df5c98bf1180463b717629972233e7cfebf5bc33f279e62edd69cd81cbd
sha512: a17f16f92720c7a726aee6ec0a9b41abc5b79af1c9c27d7e0735e4e97beba9d580c09b3c33fae36cb59c329d7096e8a225eaac323511be65dcc1b73b0f6ad30a
ssdeep: 3072:9VMKsWKxlGxE07ABigCFHdLYyBvzyBHNGqXgvnHZyzi0zslLFa/FzKsR:D3sWKxQ52CFHdLYKvzyZNGX/IupG2s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B014216BF521C054E59240B8742CEA8AF45C7E7305446972FB81BB5939B27EFA0F6B03
sha3_384: 9871e983a21f251b871da5d91b718c671a886e32ff7bedbb90579e739036b5754149556c815320b384507542346becb0
ep_bytes: 6868784000e8f0ffffff000000000000
timestamp: 2008-12-07 04:12:59

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: DOCUMENT
OriginalFilename: DOCUMENT.exe

Backdoor.VB.Agent.ABT (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.19362
MicroWorld-eScanBackdoor.VB.Agent.ABT
FireEyeGeneric.mg.4b49f4d299fdaaf2
CAT-QuickHealWorm.Copali.OD3
McAfeeW32/Worm-GAM!4B49F4D299FD
CylanceUnsafe
VIPRETrojan.Win32.Swisyn.dfkc (fs)
K7AntiVirusP2PWorm ( 00486ea71 )
K7GWP2PWorm ( 00486ea71 )
Cybereasonmalicious.299fda
BitDefenderThetaAI:Packer.254A2CEF15
CyrenW32/S-a42f8a3c!Eldorado
SymantecW32.SillyFDC
ESET-NOD32Win32/VB.OLE
TrendMicro-HouseCallWORM_COPALI_EJ200083.UVPM
ClamAVWin.Dropper.Cerber-7134131-0
KasperskyTrojan.Win32.Agentb.btmh
BitDefenderBackdoor.VB.Agent.ABT
NANO-AntivirusTrojan.Win32.TrjGen.deyzgg
SUPERAntiSpywareTrojan.Agent/Gen-Symmi
AvastWin32:Vitro [Inf]
TencentMalware.Win32.Gencirc.10b0cd1f
Ad-AwareBackdoor.VB.Agent.ABT
TACHYONTrojan/W32.Agent.196608
EmsisoftBackdoor.VB.Agent.ABT (B)
ComodoTrojWare.Win32.Swisyn.DFX@5ci87q
BaiduWin32.Worm.VB.bf
ZillyaTrojan.Swisyn.Win32.32299
TrendMicroWORM_COPALI_EJ200083.UVPM
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
SophosML/PE-A + Troj/VB-HTM
IkarusWorm.Win32.VB
JiangminTrojan/Swisyn.wsw
AviraTR/Beebone.rhwnabs
Antiy-AVLTrojan/Generic.ASMalwS.93BFFC
MicrosoftWorm:Win32/Copali.B
ViRobotTrojan.Win32.Zbot.184320.D
GDataBackdoor.VB.Agent.ABT
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C436931
Acronissuspicious
VBA32Trojan.Agentb
ALYacBackdoor.VB.Agent.ABT
MAXmalware (ai score=80)
MalwarebytesTrojan.Agent
APEXMalicious
RisingWorm.Copali!1.A2C3 (CLASSIC)
YandexTrojan.GenAsa!UB1ZEjQvu58
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/CoinMiner.F
AVGWin32:Vitro [Inf]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.VB.Agent.ABT (B)?

Backdoor.VB.Agent.ABT (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment