Trojan

About “Trojan.Win32.VB.banz” infection

Malware Removal

The Trojan.Win32.VB.banz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VB.banz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.VB.banz?


File Info:

name: 3D647C52FCB9B11E8213.mlw
path: /opt/CAPEv2/storage/binaries/552c0800d6ab1409f42f546b17fb02b4851e7e215b6d5a5fa628fe940880e55f
crc32: EC79AF29
md5: 3d647c52fcb9b11e8213f226f1bcb004
sha1: d9df0fd56230d5801124d3447b740186aaa2c47f
sha256: 552c0800d6ab1409f42f546b17fb02b4851e7e215b6d5a5fa628fe940880e55f
sha512: 71921c5fb4f686486fc259108c3aa72b5bb3134c77fb25f69177a7fe255fabceec336e3632611175725d88e3328d4061ef15b9b1af9e47e10d7af7c54414419c
ssdeep: 6144:LZXePLrhXgYIlqAnIVDC8e5uMSXGJZPBP3Jm90LFn:A/hXgYMNIVa5uM1D/U0Rn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17064B416A2C1F73DD521CAF43A5682A4993DAC3224D56807F7D21F2A73B1D9BE632313
sha3_384: 81564ef7eba3ab1afb1e185fd2ed556c675d3f7125732bfbe289f257d4ebb13c29b0157b6623f2a269f6525953350060
ep_bytes: 6830514000e8f0ffffff000000000000
timestamp: 1996-03-05 04:15:37

Version Info:

0: [No Data]

Trojan.Win32.VB.banz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.317821
ClamAVWin.Trojan.Vobfus-70360
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Lazy.317821
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Lazy.317821
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.Zyx.HI
CyrenW32/Vobfus.AI.gen!Eldorado
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.AC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VB.banz
BitDefenderGen:Variant.Lazy.317821
NANO-AntivirusTrojan.Win32.VB.rilra
AvastWin32:AutoRun-CNR [Trj]
TencentTrojan.Win32.VB.hj
EmsisoftGen:Variant.Lazy.317821 (B)
F-SecureTrojan.TR/VB.Agent.aztqc
DrWebWorm.Siggen.12141
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
FireEyeGeneric.mg.3d647c52fcb9b11e
SophosTroj/VB-FSS
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Lazy.317821
AviraTR/VB.Agent.aztqc
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Lazy.D4D97D
ViRobotTrojan.Win32.A.VB.319488.E
ZoneAlarmTrojan.Win32.VB.banz
MicrosoftWorm:Win32/Vobfus
GoogleDetected
AhnLab-V3Trojan/Win.VB.R563223
Acronissuspicious
McAfeeVBObfus.cm
TACHYONTrojan/W32.VB-Agent.323584.BS
VBA32Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.Pronoy!1.9A2F (CLASSIC)
YandexTrojan.GenAsa!szfRhegiJQQ
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaGen:NN.ZevbaF.36250.tmX@aW!8zsg
AVGWin32:AutoRun-CNR [Trj]
Cybereasonmalicious.2fcb9b
DeepInstinctMALICIOUS

How to remove Trojan.Win32.VB.banz?

Trojan.Win32.VB.banz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment