Backdoor

Backdoor.Win32.VB.aco (file analysis)

Malware Removal

The Backdoor.Win32.VB.aco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.VB.aco virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Backdoor.Win32.VB.aco?


File Info:

name: D188FD615BABAEA8EF85.mlw
path: /opt/CAPEv2/storage/binaries/2f4448f0fe1e386a8b98f3a5c5faf5611c6cd035394de3da9fa252745dcd144e
crc32: 71ADE1B2
md5: d188fd615babaea8ef85980071b37805
sha1: 69bc8260bc22385ae8e5340c01c09a2910639120
sha256: 2f4448f0fe1e386a8b98f3a5c5faf5611c6cd035394de3da9fa252745dcd144e
sha512: f448fcc1983a7d4839bffa67b5bfe82be9a133f266839e04d918211b94bc57f76a7d9d8fe0c9c76aa85dee899c4cf21aaa571d2cfd621516c3b6e08beaf69c6f
ssdeep: 3072:P3swJ4RNoZlnYxch4N6+/ugJmilyTekclCg1TGJ1uCEt8tOF5pU+E+X:P3cRN4Xhe3/ugJmilyTekICgoJnobG+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171143B339A947021E267047118BA663929327C2D2A12DD4BB265EF5D6C31983F7F732F
sha3_384: 05ecd5295c317404e1312d6bb60b2c81e667eb0a6e64f1ec6ae83a7fb394cf2acc4f29bb918ff2475e740bff749c4922
ep_bytes: 683c264000e8eeffffff000040000000
timestamp: 2007-01-01 15:59:08

Version Info:

Translation: 0x0409 0x04b0
ProductName: Server.exe
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Server
OriginalFilename: Server.exe

Backdoor.Win32.VB.aco also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.mm0@sjiM18diy
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenericRXAA-AA!D188FD615BAB
MalwarebytesGeneric.Malware/Suspicious
ZillyaBackdoor.VB.Win32.18423
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Generic.5c44051f
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.15baba
ArcabitTrojan.Heur.EE4CDB
BitDefenderThetaAI:Packer.A31944431D
VirITBackdoor.Win32.Generic.WB
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.ZT
APEXMalicious
KasperskyBackdoor.Win32.VB.aco
BitDefenderGen:Trojan.Heur.mm0@sjiM18diy
NANO-AntivirusTrojan.Win32.VB.bhpxh
AvastWin32:BackdoorX-gen [Trj]
TencentWin32.Backdoor.Vb.Wwhl
EmsisoftGen:Trojan.Heur.mm0@sjiM18diy (B)
F-SecureBackdoor.BDS/VB.zt
DrWebBackDoor.Generic.907
VIPREGen:Trojan.Heur.mm0@sjiM18diy
FireEyeGeneric.mg.d188fd615babaea8
SophosMal/Behav-131
IkarusBackdoor.Win32.VB
GoogleDetected
AviraBDS/VB.zt
Antiy-AVLTrojan[Backdoor]/Win32.VB
Kingsoftmalware.kb.a.1000
XcitiumBackdoor.Win32.VB.zt0@1o8eu2
MicrosoftBackdoor:Win32/VB
ViRobotBackdoor.Win32.A.VB.147456.B
ZoneAlarmBackdoor.Win32.VB.aco
GDataGen:Trojan.Heur.mm0@sjiM18diy
CynetMalicious (score: 99)
AhnLab-V3Malware/Gen.Generic.R443951
VBA32suspected of Backdoor.VBbot.3
ALYacGen:Trojan.Heur.mm0@sjiM18diy
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
RisingBackdoor.VB.qei (CLASSIC)
YandexTrojan.GenAsa!cojvMcFUYNc
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.49915.susgen
FortinetW32/Vb.ACO!tr.bdr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudBackdoor:Win/VB.ZT

How to remove Backdoor.Win32.VB.aco?

Backdoor.Win32.VB.aco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment