Trojan

Trojan.VBRA.09412 removal instruction

Malware Removal

The Trojan.VBRA.09412 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VBRA.09412 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.VBRA.09412?


File Info:

name: DC2AF6BF8B14518CFCEC.mlw
path: /opt/CAPEv2/storage/binaries/99b42314fc521193e1eb8f21544dab91b4ae86209d4f75dc411efafa07b76adc
crc32: 2C61A153
md5: dc2af6bf8b14518cfcec0b10f22e2191
sha1: 4bcc68c395b3b831d6a8defcf567dccdcd784336
sha256: 99b42314fc521193e1eb8f21544dab91b4ae86209d4f75dc411efafa07b76adc
sha512: ed2e5531de4796f439922bbd87b6aaa34d42b90455a73e8b4687a71186d88673cb60276e1f46d520587055c1857c746e01f23d307d4007c35504ba7e89a0c110
ssdeep: 3072:Fr46db03y4CpCfCGCCOCwC9CvCFCfCLCvCUCLC2FInROUSRSGSuSQSmSNS4SQSsW:Wib03yGFInRO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0D333FB24836D2CC61D7C73137ED6A125A379C456CB508E23B32B9B3815D60CC769AA
sha3_384: 2af02f546d3212cdcdbe219d8cb6a1d7a384e663eb8c8495f8c45c7307ff08ccf6f9bbdfabeadfe68e692498e484f2e9
ep_bytes: 68cc124000e8f0ffffff000050000000
timestamp: 1978-12-07 11:12:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: KCjTeEYI
FileVersion: 5.29
ProductVersion: 5.29
InternalName: KCjTeEYI
OriginalFilename: KCjTeEYI.exe

Trojan.VBRA.09412 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.lmeS
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.71823
FireEyeGeneric.mg.dc2af6bf8b14518c
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeDownloader-CJX.gen.g
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2f98.None
K7GWEmailWorm ( 00568ea71 )
K7AntiVirusEmailWorm ( 00568ea71 )
ArcabitTrojan.Generic.D1188F
BaiduWin32.Trojan.VB.a
VirITTrojan.Win32.Scar.LM
SymantecW32.Changeup.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.RU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.VB-1129
KasperskyTrojan.Win32.Agent.vefb
BitDefenderTrojan.GenericKDZ.71823
NANO-AntivirusTrojan.Win32.Crypt.ddyvq
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert
AvastWin32:Sality-GW [Trj]
TencentTrojan.Win32.Vbcode.a
TACHYONTrojan/W32.Agent.131072
EmsisoftTrojan.GenericKDZ.71823 (B)
F-SecureTrojan.TR/Poly.Agent.C
DrWebTrojan.Siggen5.23153
VIPRETrojan.GenericKDZ.71823
TrendMicroWORM_VB.SMRX
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.atgeb
WebrootW32.Malware.Gen
VaristW32/Vobfus.E.gen!Eldorado
AviraTR/Poly.Agent.C
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Downloader.VB.C@22k4yp
MicrosoftWorm:Win32/Vobfus.AC
ViRobotWorm.Win32.VB.131072.C
ZoneAlarmTrojan.Win32.Agent.vefb
GDataTrojan.GenericKDZ.71823
GoogleDetected
AhnLab-V3Win32/Vbna4.worm.Gen
BitDefenderThetaAI:Packer.3C5AF07720
ALYacTrojan.GenericKDZ.71823
MAXmalware (ai score=82)
VBA32Trojan.VBRA.09412
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/VobfusLNK.A
TrendMicro-HouseCallWORM_VB.SMRX
RisingWorm.Win32.Undef.ow (CLASSIC)
YandexTrojan.GenAsa!DW6iNpE2rrI
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Agent.vefb
FortinetW32/VBObfus.BDBD!tr
AVGWin32:Sality-GW [Trj]
Cybereasonmalicious.395b3b
DeepInstinctMALICIOUS

How to remove Trojan.VBRA.09412?

Trojan.VBRA.09412 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment