Malware

Mal/Generic-S + W32/VB-GAZ removal tips

Malware Removal

The Mal/Generic-S + W32/VB-GAZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + W32/VB-GAZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Mal/Generic-S + W32/VB-GAZ?


File Info:

name: BFE3B6713ACF8DA45077.mlw
path: /opt/CAPEv2/storage/binaries/15178b0df74a0863b7d2301084a2f3025a7fd081d032b79d7cac1035a591b992
crc32: 2A7233E2
md5: bfe3b6713acf8da450774506a1b87bee
sha1: 5ef4746585ae9d0169c4779c9d32175596faf6be
sha256: 15178b0df74a0863b7d2301084a2f3025a7fd081d032b79d7cac1035a591b992
sha512: 24cbf3f7b0d5a0a5870e131969f6d794a3faa8226f23329824924ec1555484481b2f0c69699af77dc52298f3f24fd662ddb8b7bbce25976e08b32af8fd9c97f8
ssdeep: 1536:IVMy3/PPqPrwZzTGRfu+1niPRI7gIeTo88zQMihZOy+RMnmE7UkAFJZvhICqDojA:7kPqPrWzTGRfu67bNz2hT9nmEzHL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB04D67F3E96214BC4A50275B6E2C7E8227B3C065F83590FE61432BA1CF2F5019396A7
sha3_384: 15ba7ce621375c15773a7a4029adbc7b466fb0137572f267a5e727e2913308c34d6dd4dc756189e7f21ca940fa9f7a4b
ep_bytes: 68d0124000e8eeffffff000068000000
timestamp: 2012-08-16 02:54:16

Version Info:

Translation: 0x0409 0x04b0
Comments: Entusiasto peaceable
CompanyName: Entusiasto peaceable
FileDescription: Entusiasto peaceable
LegalCopyright: Entusiasto peaceable
LegalTrademarks: Entusiasto peaceable
ProductName: Entusiasto peaceable
FileVersion: 0.50
ProductVersion: 0.50
InternalName: sulphonamido
OriginalFilename: sulphonamido.exe

Mal/Generic-S + W32/VB-GAZ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ClamAVWin.Malware.Vobfus-6806248-0
CAT-QuickHealWorm.VobfusMF.S18680912
McAfeeVBObfus.ek
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.VB.lg
VirITTrojan.Win32.Cryptor.RI
CyrenW32/VB.HD.gen!Eldorado
SymantecW32.Changeup!gen20
ESET-NOD32Win32/AutoRun.VB.AYH
APEXMalicious
AvastWin32:VB-AEDA [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.fdja
BitDefenderTrojan.GenericKDZ.74334
NANO-AntivirusTrojan.Win32.Jorik.cqkxva
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
MicroWorld-eScanTrojan.GenericKDZ.74334
TencentWorm.Win32.Vobfus.m
EmsisoftTrojan.GenericKDZ.74334 (B)
ComodoWorm.Win32.Pronny.ABQ@4puwz1
DrWebWin32.HLLW.Autoruner2.23981
VIPRETrojan.Win32.Vobfus.paa (v)
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
SophosMal/Generic-S + W32/VB-GAZ
Paloaltogeneric.ml
GDataTrojan.GenericKDZ.74334
JiangminTrojan/Vbobf.b
Antiy-AVLWorm/Win32.WBNA.gen
GridinsoftRansom.Win32.Zbot.sa
MicrosoftWorm:Win32/Vobfus.GZ
AhnLab-V3Trojan/Win32.Jorik.R33547
Acronissuspicious
VBA32Trojan.Vobfus
MAXmalware (ai score=89)
MalwarebytesMalware.AI.1419712213
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingTrojan.Fakefolder!1.6503 (CLASSIC)
YandexTrojan.GenAsa!IXrz+ynkfaw
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.AU!tr
BitDefenderThetaAI:Packer.B702AE6E1F
AVGWin32:VB-AEDA [Trj]
Cybereasonmalicious.13acf8
PandaTrj/Zbot.M

How to remove Mal/Generic-S + W32/VB-GAZ?

Mal/Generic-S + W32/VB-GAZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment