Backdoor

How to remove “Backdoor:Win32/VB.LU”?

Malware Removal

The Backdoor:Win32/VB.LU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/VB.LU virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/VB.LU?


File Info:

crc32: 3DA78B4D
md5: 851cb4e7a6c796add999fd3ff27bfc22
name: 851CB4E7A6C796ADD999FD3FF27BFC22.mlw
sha1: e99f9b0849a0f1c159e64baefbd49ed2ed9247ed
sha256: 3c68761218d1d4fb5de6da1f59570f865c2b6764541ae30c13301953dbad1900
sha512: cc59283872eaea77a784262325ff8d5d88588438e4161152af3a8fa7fcb7722a1492b29b7742fefb851b044e105a59477357ce4e0e8d2c285bd4551e5484d612
ssdeep: 3072:tW/oW9iT9/FPjTfSXhQiWFb3quM/CnmsNHE0WXiDDsM:t6ob/FCDGb6LYFNkDSDQM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/VB.LU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004ce0ea1 )
LionicTrojan.Win32.VB.b!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Multi.136
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaBackdoor.Poison.Win32.59685
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Carrier.257d4412
K7GWTrojan ( 004ce0ea1 )
Cybereasonmalicious.7a6c79
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.VB.NFA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Dropper.Win32.VB.amgf
BitDefenderTrojan.Ransom.Petya.Gen.1
NANO-AntivirusTrojan.Win32.Multi.ecjwpp
MicroWorld-eScanTrojan.Ransom.Petya.Gen.1
TencentWin32.Trojan-dropper.Vb.Dxwm
Ad-AwareTrojan.Ransom.Petya.Gen.1
ComodoMalware@#1hh8by17ilbln
BitDefenderThetaAI:Packer.BC61B5641D
VIPRETrojan.Win32.Agent.aac (v)
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.851cb4e7a6c796ad
EmsisoftTrojan.Ransom.Petya.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.VB.ngb
AviraTR/Dropper.Gen
eGambitGeneric.Dropper
Antiy-AVLTrojan/Generic.ASMalwS.1ECDF8
MicrosoftBackdoor:Win32/VB.LU
GDataTrojan.Ransom.Petya.Gen.1
AhnLab-V3Trojan/Win32.Llac.C368828
McAfeeArtemis!851CB4E7A6C7
MAXmalware (ai score=100)
VBA32BScope.Trojan.871206
MalwarebytesMalware.AI.3976976637
PandaTrj/CI.A
RisingTrojan.Generic@ML.99 (RDMK:TLZjbX01Nfea7tbovuik8Q)
IkarusWorm.Win32.Carrier
FortinetW32/Generic.AC.2AD7!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Worm.VB.HgIASOgA

How to remove Backdoor:Win32/VB.LU?

Backdoor:Win32/VB.LU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment