Trojan

Trojan.VB.Bugsban.A information

Malware Removal

The Trojan.VB.Bugsban.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VB.Bugsban.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Executes the printer spooler process
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.VB.Bugsban.A?


File Info:

name: 58BC309BB13898BDAB5E.mlw
path: /opt/CAPEv2/storage/binaries/1038ec6ccefcd097942af0d34244e205fa04635386629acc00734e8d82955c1a
crc32: C1E2B484
md5: 58bc309bb13898bdab5e55fbb384cdcf
sha1: d106e56cd3ee7d567f275aa4fb7a93d97f307f91
sha256: 1038ec6ccefcd097942af0d34244e205fa04635386629acc00734e8d82955c1a
sha512: b8fe1447b2a1cec08ff2bc383bb2324c23d07e966bc3b95321bb50716bcfed0efe3c21061aeb4632e42a19d30aab9805324b9d0e504f25e40451c6778d364643
ssdeep: 1536:GeK40T/mx7y9v7Z/Z2V/GSAFRfBWBrLrV7VoK:GD40Dmx7y9DZ/Z2hG6rLrVaK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1A36C0BB7CD1897DA5B6B3955E782B886237D5F9A538B873114333E2C31F022D3A652
sha3_384: e309b04fab2941c3156cb17ae768036a9eb68e1ecf735ef2d106cfa7410dc38a9196e6d4c7b86346ccd6b0de296b12af
ep_bytes: 68c0354000e8eeffffff000000000000
timestamp: 2003-08-06 18:34:23

Version Info:

0: [No Data]

Trojan.VB.Bugsban.A also known as:

BkavW32.AIDetectMalware
DrWebWin32.HLLW.Adeka
MicroWorld-eScanTrojan.VB.Bugsban.A
ClamAVWin.Worm.Rungbu-6750017-0
FireEyeGeneric.mg.58bc309bb13898bd
ALYacTrojan.VB.Bugsban.A
Cylanceunsafe
ZillyaWorm.VB.Win32.61427
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
BitDefenderThetaAI:Packer.6D95E3AE1E
VirITWorm.Win32.VB.ZS
CyrenW32/VB-Backdoor-HRS-based!Maxim
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.NHI
ZonerTrojan.Win32.33052
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.VB.du
BitDefenderTrojan.VB.Bugsban.A
NANO-AntivirusTrojan.Win32.VB.vdws
AvastWin32:VB-AXO [Wrm]
TencentMalware.Win32.Gencirc.10bea0a3
EmsisoftTrojan.VB.Bugsban.A (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.Begolu.a
VIPRETrojan.VB.Bugsban.A
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
Trapminemalicious.high.ml.score
SophosW32/Rungbu-A
IkarusTrojan-Spy.Win32.Zbot
GDataWin32.Virus.Rungflu.A
JiangminWorm/VB.ct
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.VB.du
XcitiumWorm.Win32.VB.NHI@252y
ArcabitTrojan.VB.Bugsban.A
ZoneAlarmWorm.Win32.VB.du
MicrosoftVirus:Win32/Rungbu.A
GoogleDetected
AhnLab-V3Worm/Win32.AutoRun.C61589
Acronissuspicious
McAfeeW32/Rungbu
MAXmalware (ai score=85)
VBA32Trojan.VBS.01813
MalwarebytesVirut.Virus.FileInfector.DDS
PandaW32/Rungbu.B.worm
RisingBackdoor.Agent!1.69CE (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/VB.DU!worm
AVGWin32:VB-AXO [Wrm]
DeepInstinctMALICIOUS

How to remove Trojan.VB.Bugsban.A?

Trojan.VB.Bugsban.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment