Malware

Troj/VB-FSK (file analysis)

Malware Removal

The Troj/VB-FSK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/VB-FSK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Troj/VB-FSK?


File Info:

name: DD169A09542ADE501A7A.mlw
path: /opt/CAPEv2/storage/binaries/500f1d7168b42001c2b1356a366677bb1ec1165e91a88939c86e92662e474b50
crc32: E35427E2
md5: dd169a09542ade501a7a0f8ad1cc221a
sha1: 792c059323f503fbb53bee024485c6b905bdbd9b
sha256: 500f1d7168b42001c2b1356a366677bb1ec1165e91a88939c86e92662e474b50
sha512: 11b45cbe63c7a1c4ec368114e74422861518caec3858d478ba1939369d15844cc70bcb94520bd4acf261bf3707db4b165b71ad19185e6867da2d40589d486293
ssdeep: 6144:nfXim9AN+tytpx96Hg02BCh3FZuhbYaxUG2nIVeUuto:nfXiAfyDxsHg02BCh3FZuhbYaxUG2npQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16354E7297390FB3AE065C1F13A5A83A4553EED7624A4A807F7D22F2A73B0D57D061723
sha3_384: 9d24d393b1959af6e4967168f292b9635b9fdb8c8c16438476b66590d7bcf7961c6f01db412042884a3155b8fae67119
ep_bytes: 68ac434000e8f0ffffff000040000000
timestamp: 2012-01-04 19:14:12

Version Info:

0: [No Data]

Troj/VB-FSK also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.4173
FireEyeGeneric.mg.dd169a09542ade50
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Ser.Zusy.4173
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Zyx.HC
SymantecW32.Changeup!gen15
ESET-NOD32Win32/AutoRun.VB.AQE
APEXMalicious
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.dfhy
BitDefenderGen:Variant.Ser.Zusy.4173
NANO-AntivirusTrojan.Win32.VB.chvyxv
AvastWin32:AutoRun-CMJ [Trj]
TencentWorm.Win32.Vobfus.kay
EmsisoftGen:Variant.Ser.Zusy.4173 (B)
F-SecureTrojan.TR/Jorik.Vobfus.klo
DrWebTrojan.VbCrypt.150
TrendMicroTROJ_AGENT_006413.TOMB
Trapminemalicious.moderate.ml.score
SophosTroj/VB-FSK
IkarusSality.Win32
GoogleDetected
AviraTR/Jorik.Vobfus.klo
VaristW32/Vobfus.AI.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!P
XcitiumWorm.Win32.Vobfus.MJ@8ekc4q
ArcabitTrojan.Ser.Zusy.D104D
ViRobotWorm.Win32.A.WBNA.294912.S
ZoneAlarmWorm.Win32.Vobfus.dfhy
GDataGen:Variant.Ser.Zusy.4173
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R36357
Acronissuspicious
BitDefenderThetaAI:Packer.2C00F6471E
ALYacGen:Variant.Ser.Zusy.4173
MAXmalware (ai score=83)
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_006413.TOMB
RisingWorm.Pronoy!1.9A2F (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Diple.EJQE!tr
AVGWin32:AutoRun-CMJ [Trj]
DeepInstinctMALICIOUS

How to remove Troj/VB-FSK?

Troj/VB-FSK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment