Trojan

Should I remove “Trojan.VB.Gen”?

Malware Removal

The Trojan.VB.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VB.Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Trojan.VB.Gen?


File Info:

name: 0B36DDA83705DCA33261.mlw
path: /opt/CAPEv2/storage/binaries/6b07b1bb32c02a51f0b2352b81a79e258fc6765d51cd81fe5be42abddd16c6df
crc32: BC986AF3
md5: 0b36dda83705dca33261b02cf29fb2c0
sha1: 76ba2ab3b27d38c420563edb9f9dce599ac05d03
sha256: 6b07b1bb32c02a51f0b2352b81a79e258fc6765d51cd81fe5be42abddd16c6df
sha512: 3e020d9b7e43969e76d2a911a3897f1a5744c7785207e6816fb8d121c5eabe8e8defcb7df4ab0bdf4f7887fcf36d8f359a3e9aafde5cab09773ccb76cefad961
ssdeep: 3072:3F2PCMoNjOHtggMg8wDHhDjgv9d30dPu262yS1NTFohfQ4UwrQUhDP9QDJWmvKKT:3UPRoNeSVhE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA64C31DAAFF041BE44DC2B42FC0E87F4894E73725A5AD342DD84BD90A58D4479EB23A
sha3_384: 718bd8c34842f57265661c77781ed4cceed44ad986c612349d996f7920f2d38b04becc09361c77a7b0900ae56e9f8ba3
ep_bytes: 6890174000e8f0ffffff000000000000
timestamp: 2011-08-13 08:27:54

Version Info:

Translation: 0x0409 0x04b0
Comments: LrABzEpiqThgwAC
CompanyName: adsNOYidGVpIc
FileDescription: lSkVaAomgyvRoMR
LegalCopyright: qhuFonbMoK
ProductName: LVqEreEbaC
FileVersion: 1.00
ProductVersion: 1.00
InternalName: video
OriginalFilename: video.exe

Trojan.VB.Gen also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.ManBat.1
FireEyeGeneric.mg.0b36dda83705dca3
CAT-QuickHealTrojan.VB.Gen
ALYacGen:Heur.ManBat.1
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1582939
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.83705d
CyrenW32/VBKrypt.BHG.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.HKF
APEXMalicious
KasperskyTrojan.Win32.Agent.zmve
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.CFI.fllact
AvastWin32:Inject-ALI [Trj]
TencentMalware.Win32.Gencirc.10d0b016
Ad-AwareGen:Heur.ManBat.1
EmsisoftGen:Heur.ManBat.1 (B)
VIPREGen:Heur.ManBat.1
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.hmvrw
GoogleDetected
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan/Generic.ASMalwS.51F4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Heur.ManBat.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Malco.R7759
Acronissuspicious
McAfeeGenericRXAA-AA!0B36DDA83705
MAXmalware (ai score=81)
VBA32BScope.Trojan.VB.01559
MalwarebytesMalware.AI.2791285831
RisingHackTool.VBInject!1.6481 (CLASSIC)
YandexTrojan.Agent!upsNcaRDVns
FortinetW32/Injector.HKF!tr
BitDefenderThetaGen:NN.ZevbaF.34698.tm1@aepOlIni
AVGWin32:Inject-ALI [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.VB.Gen?

Trojan.VB.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment