Malware

Troj/VBinj-YK malicious file

Malware Removal

The Troj/VBinj-YK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/VBinj-YK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Troj/VBinj-YK?


File Info:

name: 5CA6599A854D8CB782F7.mlw
path: /opt/CAPEv2/storage/binaries/eb531933c7fb12e8e414e7d687f7c660d4890f384331329c0d17d6a3f86862c4
crc32: A36BA7CC
md5: 5ca6599a854d8cb782f7a71cc7d54d24
sha1: 34def6da843c61b8b4ef61a14c860d879ba7433e
sha256: eb531933c7fb12e8e414e7d687f7c660d4890f384331329c0d17d6a3f86862c4
sha512: d6787c71c965d4a2af37506b50f423ec9452334d332180f75cdbda53a406894796dc8c955a4998b1fbc48a6e2f905e2606c40508bd43c43d4639203d15b7f5b0
ssdeep: 3072:/yxtND50tQ9nLHbB9WJvA7DejJuKvEhfm:854QxL7B9WSvejJuB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16434E5937F36B445F86565306CFB86FA7783F88C4A0701475B30226A9EDBE722D24693
sha3_384: d5bdddd3f8fee6b6e6fb7f18e98bf1ca8c9fe0d22c5977bd20e601b93c788811cd5b2da706714d5562640e12a2c0bc16
ep_bytes: 6824124000e8eeffffff000000000000
timestamp: 2002-06-21 10:26:09

Version Info:

0: [No Data]

Troj/VBinj-YK also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Acnu-7601993-0
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dt
ALYacGeneric.Dacic.0B66ABC5.A.E5EF630E
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGeneric.Dacic.0B66ABC5.A.E5EF630E
K7GWEmailWorm ( 003c363a1 )
K7AntiVirusEmailWorm ( 003c363a1 )
BaiduWin32.Worm.VB.mf
VirITTrojan.Win32.Cryptor.H
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AVF
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VB.budw
NANO-AntivirusTrojan.Win32.VB.rilpg
ViRobotTrojan.Win32.A.VB.200704.H
MicroWorld-eScanGeneric.Dacic.0B66ABC5.A.E5EF630E
AvastWin32:VB-ADDH [Trj]
RisingWorm.Pronny!1.E3E8 (CLASSIC)
SophosTroj/VBinj-YK
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.15097
VIPREGeneric.Dacic.0B66ABC5.A.E5EF630E
TrendMicroTROJ_AGENT_037768.TOMB
FireEyeGeneric.mg.5ca6599a854d8cb7
EmsisoftGeneric.Dacic.0B66ABC5.A.E5EF630E (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/VB.clfr
VaristW32/Agent.GOO.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLVirus/Win64.Expiro.rsrc
Kingsoftmalware.kb.a.1000
MicrosoftPWS:Win32/Fareit!pz
XcitiumTrojWare.Win32.VB.AVF@4ol6o1
ArcabitGeneric.Dacic.0B66ABC5.A.E5EF630E
ZoneAlarmTrojan.Win32.VB.budw
GDataWin32.Trojan.PSE1.ARBXVV
GoogleDetected
AhnLab-V3Trojan/Win.VB.R560502
Acronissuspicious
McAfeeVBObfus.dv
TACHYONTrojan/W32.VB-Agent.245760.BS
VBA32SScope.Malware-Cryptor.VBCR.3042
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_037768.TOMB
TencentTrojan.Win32.Vb.wb
YandexTrojan.GenAsa!dMYWIGcmXQw
IkarusWorm.Win32.AutoRun
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36680.pqZ@aW6Pgvm
AVGWin32:VB-ADDH [Trj]
DeepInstinctMALICIOUS

How to remove Troj/VBinj-YK?

Troj/VBinj-YK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment