Trojan

MAS.Trojan.VB.01049 information

Malware Removal

The MAS.Trojan.VB.01049 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MAS.Trojan.VB.01049 virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MAS.Trojan.VB.01049?


File Info:

crc32: 69840FB2
md5: 5dfa705cda0e2a8a2ed70a5644c5b4ef
name: clumsy.exe
sha1: 67f9a3a6ca5d71d8e65329636ff5bbf26ea58875
sha256: 8f91a7f7c0e5e9043dd52174a1c2f135af77513fb33402516668172f73c57bc3
sha512: 9005bd0a5b445a60c508db72dd2518ad5db6ceb8565c8a966186fd72492483fbd9a0524c87623b734872d23199521518fed36c0cdf0ee9fdc4eedd01e24740f4
ssdeep: 24576:Z5xolYQY6DvmKHzgNUoSFgDTCWymt2AbLemh01UWj:cY+mctoSFgvCWymBvemy1UWj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Win
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Win
ProductVersion: 1.00
OriginalFilename: Win.exe

MAS.Trojan.VB.01049 also known as:

BkavW32.VBOverlayD.PE
MicroWorld-eScanTrojan.Generic.6753864
FireEyeGeneric.mg.5dfa705cda0e2a8a
CAT-QuickHealTrojan.Mofksys.A
McAfeeW32/Swisyn.ag
CylanceUnsafe
VIPRETrojan-PWS.Win32.VB.cu (v)
SangforMalware
K7AntiVirusTrojan ( 0040f0591 )
BitDefenderTrojan.Generic.6753864
K7GWTrojan ( 0040f0591 )
Cybereasonmalicious.cda0e2
TrendMicroPE_MOFKSYS.A
BaiduWin32.Trojan.VB.at
F-ProtW32/VB.AD.gen!Eldorado
SymantecW32.Gosys
TotalDefenseWin32/VB.BOP
APEXMalicious
AvastWin32:VB-AJKP [Trj]
ClamAVWin.Virus.Sality:1-6335700-1
GDataTrojan.Generic.6753864
KasperskyTrojan.Win32.Swisyn.bner
NANO-AntivirusTrojan.Win32.Swisyn.efyboj
TencentTrojan.Win32.Swisyn.f
Ad-AwareTrojan.Generic.6753864
SophosTroj/VB-JVT
ComodoTrojWare.Win32.VB.OSKB@4pc2ok
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen6.54687
ZillyaTrojan.Swisyn.Win32.32298
Invinceaheuristic
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Swisyn!O
EmsisoftTrojan.Generic.6753864 (B)
IkarusTrojan-Spy.MSIL.Omaneat
CyrenW32/VB.AD.gen!Eldorado
JiangminTrojan/Swisyn.rmj
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Swisyn.bner
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D670E48
ZoneAlarmTrojan.Win32.Swisyn.bner
MicrosoftPWS:Win32/VB.CU
AhnLab-V3Trojan/Win32.Swisyn.R1452
Acronissuspicious
BitDefenderThetaAI:Packer.DEC4880A20
ALYacTrojan.Generic.6753864
MAXmalware (ai score=84)
VBA32MAS.Trojan.VB.01049
MalwarebytesTrojan.VBCrypt
PandaGeneric Malware
ZonerTrojan.Win32.47063
ESET-NOD32Win32/VB.OSK
TrendMicro-HouseCallPE_MOFKSYS.A
RisingTrojan.QOT!1.6519 (CLASSIC)
YandexTrojan.VBGent.Gen.471
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Swisyn.BNER
FortinetW32/Swisyn.BNER!tr
AVGWin32:VB-AJKP [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.1375.Malware.Gen

How to remove MAS.Trojan.VB.01049?

MAS.Trojan.VB.01049 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment