Trojan

What is “Trojan.Agent.VB.BNU”?

Malware Removal

The Trojan.Agent.VB.BNU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.VB.BNU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Detects Bochs through the presence of a registry key
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Agent.VB.BNU?


File Info:

name: 9A4C84EB08C6CE7B9D4E.mlw
path: /opt/CAPEv2/storage/binaries/ec1cab41f89a6f4e1542c46ee7645a71686c02efcf7331e860827835561ee6c5
crc32: 3C2D563C
md5: 9a4c84eb08c6ce7b9d4ec35d93eea544
sha1: e8ce387f5c3bd7477a7acc7f29511e6dc81407d0
sha256: ec1cab41f89a6f4e1542c46ee7645a71686c02efcf7331e860827835561ee6c5
sha512: ef40973d552521750f897687cd93fa7c3410d7115150ae90ab0ba87bb3830f6f54b5a766431f72bed4b986901d157d7dddebb81f44364381fdeec3e1f15e1efa
ssdeep: 3072:11pPFVEK0p4D4dMz4n4N4t4R4aEIIIIzX:11pPnSxMdEIIIIz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180B3B63DB2C52480F7695473F7BE88FF0288684A1747913530BB5D8AAF5AE80D1749AF
sha3_384: b63994420bb1d8480ef4b966e8dc9778be3ec5a2a8226411b71bc1568475708ed562b8b0aea5bdb7773673b99530d8b3
ep_bytes: 689c124000e8eeffffff000040000000
timestamp: 2010-07-22 15:56:05

Version Info:

Translation: 0x0409 0x04b0
ProductName: xn
FileVersion: 2.44
ProductVersion: 2.44
InternalName: ttbWLKZS
OriginalFilename: ttbWLKZS.exe

Trojan.Agent.VB.BNU also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.VB.BNU
ClamAVWin.Trojan.VB-1139
FireEyeGeneric.mg.9a4c84eb08c6ce7b
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeDownloader-CJX.gen.g
Cylanceunsafe
ZillyaWorm.VBNA.Win32.91719
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00568ea91 )
AlibabaWorm:Win32/Vobfus.ba5f4268
K7GWEmailWorm ( 00568ea91 )
Cybereasonmalicious.f5c3bd
BitDefenderThetaGen:NN.ZevbaF.36680.gm0@aepTVGdi
VirITTrojan.Win32.Scar.LR
SymantecW32.Changeup.C
ESET-NOD32Win32/AutoRun.VB.RP
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.VBNA.alzd
BitDefenderTrojan.Agent.VB.BNU
NANO-AntivirusTrojan.Win32.Drop.covlpa
ViRobotWorm.Win32.Vobfus.113664
AvastWin32:AutoRun-BLX [Wrm]
TencentWorm.Win32.Vbna.ze
TACHYONWorm/W32.VBNA.113664
EmsisoftTrojan.Agent.VB.BNU (B)
BaiduWin32.Trojan.VB.a
F-SecureWorm:W32/Vobfus.BS
DrWebWin32.HLLW.Autoruner.36804
VIPRETrojan.Agent.VB.BNU
TrendMicroWORM_VB.SMRX
SophosW32/Dulkis-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.VB.BNU
JiangminWorm/VBNA.gwrl
WebrootW32.Obfuscated.Gen
VaristW32/Vobfus.I.gen!Eldorado
AviraTR/Drop.PicHut.D
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.VBNA.alzd
XcitiumTrojWare.Win32.VB.SWA@527lh3
ArcabitTrojan.Agent.VB.BNU
SUPERAntiSpywareTrojan.Agent/Gen-CDesc[Gen]
ZoneAlarmWorm.Win32.VBNA.alzd
MicrosoftWorm:Win32/Vobfus!pz
GoogleDetected
AhnLab-V3Win32/Vbna4.worm.Gen
ALYacTrojan.Agent.VB.BNU
MAXmalware (ai score=100)
VBA32Trojan.VBRA.011141
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/VobfusLNK.A
TrendMicro-HouseCallWORM_VB.SMRX
RisingWorm.Autorun!1.99ED (CLASSIC)
YandexTrojan.GenAsa!lO0/27LUQ+8
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.1426164.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:AutoRun-BLX [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.VB.BNU?

Trojan.Agent.VB.BNU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment