Trojan

About “Trojan.Joiner.VB” infection

Malware Removal

The Trojan.Joiner.VB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Joiner.VB virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Joiner.VB?


File Info:

crc32: 1BE3B1AD
md5: ea410df758d50fc44377fe559772f547
name: oxi.exe
sha1: c9c7b23b5c56c494dc3c38f9f81102967376d844
sha256: d6042643bae320cd759736bc168a4afd1e126a520cf733a9a08da042861051a7
sha512: f4191b4f8a124b8f6b29851a396c6c4487b28dcbbe1b702819c288008edb5f7123ddded3eea873c5ea8423e5025054606436aa90108cc44f336c8645187c1368
ssdeep: 24576:kVtqdNe0+DTMbbSkSb8hSwTRCft5DqQldtD3D9FEGqhLFrXMmg:kjqN2DTSArwxcdhpFEJLFrc9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: OXI Joiner
FileVersion: 1.4.1.0
CompanyName: VaZoNeZ Corp.
LegalTrademarks:
ProductName:
ProductVersion: 1.4.1.0
FileDescription: OXI Joiner
OriginalFilename: OXI Joiner
Translation: 0x0419 0x04e3

Trojan.Joiner.VB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.MSIL.Injector.MF
FireEyeGeneric.mg.ea410df758d50fc4
McAfeeGenericRXAC-LG!EA410DF758D5
CylanceUnsafe
VIPREDetect.Trojan.Win32.Small.nmm (v)
SangforMalware
K7AntiVirusBackdoor ( 0040f6fb1 )
BitDefenderTrojan.MSIL.Injector.MF
K7GWBackdoor ( 0040f6fb1 )
Cybereasonmalicious.758d50
TrendMicroTROJ_VBINDER.SM
BitDefenderThetaAI:Packer.3DDEE67B1C
CyrenW32/GenTroj.S.gen!Eldorado
SymantecTrojan.Dropper!g1
BaiduWin32.Trojan-Dropper.Small.o
APEXMalicious
AvastWin32:GenMalicious-NUS [Trj]
ClamAVWin.Trojan.Poison-8692
GDataWin32.Trojan-Dropper.Agent.AMY
KasperskyBackdoor.Win32.Poison.ggrf
NANO-AntivirusTrojan.Win32.Poison.cbeljp
ViRobotBackdoor.Win32.Agent.67584.L
TencentMalware.Win32.Gencirc.10b3e7f9
Endgamemalicious (high confidence)
SophosTroj/Vbinder-D
ComodoTrojWare.Win32.Ransom.Xorist.ET@4mg4hg
F-SecureHeuristic.HEUR/AGEN.1114161
DrWebTrojan.MulDrop8.22787
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.Poison!O
EmsisoftTrojan.MSIL.Injector.MF (B)
IkarusBackdoor.Poison
F-ProtW32/GenTroj.S.gen!Eldorado
JiangminBackdoor/Poison.abtg
AviraHEUR/AGEN.1114161
ArcabitTrojan.MSIL.Injector.MF
ZoneAlarmBackdoor.Win32.Poison.ggrf
MicrosoftVirTool:Win32/Vbinder
AhnLab-V3Backdoor/Win32.Poison.R72119
Acronissuspicious
VBA32Backdoor.Poison
ALYacTrojan.MSIL.Injector.MF
MAXmalware (ai score=82)
Ad-AwareTrojan.MSIL.Injector.MF
MalwarebytesTrojan.Joiner.VB
PandaTrj/Injector.BH
ESET-NOD32Win32/TrojanDropper.Small.NMM
TrendMicro-HouseCallTROJ_VBINDER.SM
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqqB4+bQlLVahOgVzqpe2ES)
YandexTrojan.Oxij.Gen.LA
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Xorist.ET!tr
WebrootW32.Dropper.Gen
AVGWin32:GenMalicious-NUS [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM20.1.F1B6.Malware.Gen

How to remove Trojan.Joiner.VB?

Trojan.Joiner.VB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment