Trojan

Trojan.VB.OJW (file analysis)

Malware Removal

The Trojan.VB.OJW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VB.OJW virus can do?

  • Executable code extraction
  • Expresses interest in specific running processes
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Attempts to disable System Restore
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz

How to determine Trojan.VB.OJW?


File Info:

crc32: 83EA0B7B
md5: bb85525c93f1aa7906f32eec316a424c
name: BB85525C93F1AA7906F32EEC316A424C.mlw
sha1: 9a3d4cfcb51448d9ed40c5ada1d3fb7a6c986883
sha256: f91f31f79876f04e2e964c8d3260f909c238550da40dd2fe9fd38b08606bd34f
sha512: 5d8b946d7db955a0b41e3779c5436c9923b2bb1925908e36e14a52188f91c372bb1122edb8d211c5986029948608d7cf9a31eba99168d8ec5d16e5637ed31780
ssdeep: 3072:Ax/5F/E7tEf0U+p+tYlpJH7iXQNgggHlxDZiYLK5Wpht4xZVX42:AxhF4cp+wWJH7igNgjdFKsCRf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: DATA
FileVersion: 0.00.0020
CompanyName: Oncom
ProductName: xk
ProductVersion: 0.00.0020
OriginalFilename: DATA.exe

Trojan.VB.OJW also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.VB.OJW
FireEyeGeneric.mg.bb85525c93f1aa79
CAT-QuickHealWorm.Ludbaruma.A3
ALYacTrojan.VB.OJW
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPREWorm.Win32.Ludbaruma.a (v)
K7AntiVirusTrojan ( 0040f6141 )
BitDefenderTrojan.VB.OJW
K7GWP2PWorm ( 0050fa4b1 )
Cybereasonmalicious.c93f1a
BitDefenderThetaAI:Packer.D9B5E1A91D
CyrenW32/S-2ee348b2!Eldorado
SymantecBloodhound.W32.VBWORM
BaiduWin32.Worm.VB.k
APEXMalicious
AvastWin32:Emotet-AI [Trj]
ClamAVWin.Worm.Untukmu-5949608-0
KasperskyTrojan-Ransom.Win32.Blocker.kpuo
NANO-AntivirusTrojan.Win32.Regrun.dxtouo
ViRobotTrojan.Win32.Ludbaruma.Gen.A
Ad-AwareTrojan.VB.OJW
SophosML/PE-A + W32/Mato-N
ComodoTrojWare.Win32.Injector.FZZA@57zyc0
F-SecureTrojan.TR/Agent.gdnw
DrWebTrojan.DownLoader7.3730
ZillyaTrojan.RegrunGen.Win32.1
TrendMicroTSPY_LUDBARUMA_BK083EDB.TOMC
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.dm
EmsisoftTrojan.VB.OJW (B)
SentinelOneStatic AI – Malicious PE – Worm
JiangminTrojan.Blocker.tav
AviraTR/Agent.gdnw
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Unknown
ArcabitTrojan.VB.OJW
SUPERAntiSpywareWorm.Ludbaruma/Variant
ZoneAlarmTrojan-Ransom.Win32.Blocker.kpuo
GDataWin32.Worm.Ludbaruma.A
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.IRCBot.R1456
Acronissuspicious
McAfeeW32/Rontokbro.gen@MM
TACHYONTrojan/W32.VB-Ludbaruma.Zen.B
VBA32TScope.Trojan.VB
PandaTrj/Genetic.gen
ZonerTrojan.Win32.70598
ESET-NOD32Win32/VB.ORD
TrendMicro-HouseCallTSPY_LUDBARUMA_BK083EDB.TOMC
RisingTrojan.VB!1.BDC8 (CLASSIC)
YandexTrojan.GenAsa!3Dzo+yWZn14
IkarusTrojan.AgentMB.VB
MaxSecureTrojan-Ransom.Win32.Blocker.kpuo
FortinetW32/Regrun.PKE!tr
AVGWin32:Emotet-AI [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Worm.FakeFolder.HU

How to remove Trojan.VB.OJW?

Trojan.VB.OJW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment