Trojan

How to remove “Trojan.Agent.VB.BNU (B)”?

Malware Removal

The Trojan.Agent.VB.BNU (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.VB.BNU (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.VB.BNU (B)?


File Info:

name: AC4EE40A7A65A3104364.mlw
path: /opt/CAPEv2/storage/binaries/19707d9779002143866cffe2df765f9813a77b39bba5dae9a7acb72f594b731e
crc32: 18DBB755
md5: ac4ee40a7a65a3104364806951a33440
sha1: 26283b30d915120805c435bc6b322c6e70736c67
sha256: 19707d9779002143866cffe2df765f9813a77b39bba5dae9a7acb72f594b731e
sha512: 7efa9d9b1467757d0bb6aa3272d1cf8304d286575fb0a8f255b1b0749f8994c4e9ca0c1c274fba1e8aaff4ae5fda10b29ef4cec68229d24f58381f973cdd299f
ssdeep: 3072:b1m7Rv7YPRp4D4dMz4n4N4t4R4aEIIIIze:b1m7h7SxMdEIIIIz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6B3C73DB2C52480F2695473F7BE89FF0188684A1747913930BB5D8EAF5AE80D1749AF
sha3_384: 6be7b142d8ebae7178ca49647a20f17e60f787f1e9fea2e149f63a27382633d5736cc0168c46142a22920b2f12979dab
ep_bytes: 689c124000e8eeffffff000040000000
timestamp: 2010-07-22 15:56:05

Version Info:

Translation: 0x0409 0x04b0
ProductName: xn
FileVersion: 5.81
ProductVersion: 5.81
InternalName: dggnOjPS
OriginalFilename: dggnOjPS.exe

Trojan.Agent.VB.BNU (B) also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.lmeS
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.VB.BNU
FireEyeGeneric.mg.ac4ee40a7a65a310
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeDownloader-CJX.gen.g
Cylanceunsafe
ZillyaWorm.VBNA.Win32.62358
SangforSuspicious.Win32.Save.a
AlibabaWorm:Win32/Vobfus.ba5f4268
K7GWEmailWorm ( 00568ea91 )
K7AntiVirusEmailWorm ( 00568ea91 )
BaiduWin32.Trojan.VB.a
VirITTrojan.Win32.Scar.LR
SymantecW32.Changeup.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.RP
APEXMalicious
TrendMicro-HouseCallWORM_VB.SMRX
Paloaltogeneric.ml
ClamAVWin.Trojan.VB-1139
KasperskyWorm.Win32.VBNA.alzd
BitDefenderTrojan.Agent.VB.BNU
NANO-AntivirusTrojan.Win32.Drop.covlpa
SUPERAntiSpywareTrojan.Agent/Gen-CDesc[Gen]
AvastWin32:AutoRun-BLX [Wrm]
RisingWorm.Autorun!1.99ED (CLASSIC)
EmsisoftTrojan.Agent.VB.BNU (B)
F-SecureWorm:W32/Vobfus.BS
DrWebWin32.HLLW.Autoruner.36804
VIPRETrojan.Agent.VB.BNU
TrendMicroWORM_VB.SMRX
Trapminemalicious.moderate.ml.score
SophosW32/Dulkis-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
GDataTrojan.Agent.VB.BNU
JiangminWorm/VBNA.gwrl
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Drop.PicHut.D
VaristW32/Vobfus.I.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumMalware@#2qo0a5yreir30
ArcabitTrojan.Agent.VB.BNU
ViRobotWorm.Win32.Vobfus.113664
ZoneAlarmWorm.Win32.VBNA.alzd
MicrosoftWorm:Win32/Vobfus!pz
CynetMalicious (score: 100)
AhnLab-V3Win32/Vbna4.worm.Gen
BitDefenderThetaGen:NN.ZevbaF.36804.gm0@aepTVGdi
ALYacTrojan.Agent.VB.BNU
TACHYONWorm/W32.VBNA.113664
VBA32Trojan.VBRA.011141
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/VobfusLNK.A
TencentWorm.Win32.Vbna.ze
YandexTrojan.GenAsa!lO0/27LUQ+8
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.1426164.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:AutoRun-BLX [Wrm]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/VBNA.alzd

How to remove Trojan.Agent.VB.BNU (B)?

Trojan.Agent.VB.BNU (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment