Trojan

About “Trojan.Win32.VB.bbhv” infection

Malware Removal

The Trojan.Win32.VB.bbhv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VB.bbhv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.VB.bbhv?


File Info:

name: F1EEFCBE0D0C5A152B1B.mlw
path: /opt/CAPEv2/storage/binaries/0ca1dda17f3b8c0617fe5322564a914d66bff90d09b8533d14f57c3e1179db8c
crc32: 3A1C993E
md5: f1eefcbe0d0c5a152b1baec8133c5e31
sha1: fcf751de31d44fc13c5b6c16bfdd8da7f232b129
sha256: 0ca1dda17f3b8c0617fe5322564a914d66bff90d09b8533d14f57c3e1179db8c
sha512: 521ce09febb97564e545eb6aca859732c3a3be140ae4fca0fd507445cf28a2286e849a3e829e080e0ff5460e09124084f91c3feaca6c03f55569cbaab0f0183d
ssdeep: 768:pTX6mpnB2N/pnwfUQ6+9A/v/bVlbdfs3OfKDHGIHY56WpWoCrvrgrhG3:pTX6rp4UQ6y43wY56WpWoCrvrgr8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7A31B6BB353158AC50873BA392787C2126374179F9B50C372563BFAA837E4249BE247
sha3_384: dc87d057e9127ddd35d72429d239efcfc9622981961154ac8e54995c1ce0c142b1baabc518537e198a5c1f19d4179099
ep_bytes: 6854124000e8f0ffffff000000000000
timestamp: 2009-10-08 08:25:28

Version Info:

0: [No Data]

Trojan.Win32.VB.bbhv also known as:

BkavW32.AIDetectMalware
CAT-QuickHealTrojan.Vobfus.gen
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00568ec01 )
K7GWEmailWorm ( 00568ec01 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.VB.IM
CyrenW32/Vobfus.D.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VB.bbhv
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.AutoRun.fjzkru
ViRobotWorm.Win32.A.VBNA.61440.GM
AvastWin32:VB-NIK [Wrm]
TencentWorm.Win32.VBna.f
F-SecureWorm:W32/Vinkus.gen!A
DrWebTrojan.MulDrop.39230
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VBNA.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.nz
Trapminemalicious.high.ml.score
SophosMal/AutoRun-J
SentinelOneStatic AI – Malicious PE
AviraWORM/VBNA.JDX
Antiy-AVLTrojan/Win32.VB
XcitiumWorm.Win32.VBNA.~gen@1qlvkj
ArcabitTrojan.Chinky.2
ZoneAlarmTrojan.Win32.VB.bbhv
GoogleDetected
AhnLab-V3Win32/Vbna4.worm.Gen
Acronissuspicious
VBA32SScope.Trojan.VB.Svchorse.026
TACHYONTrojan/W32.VB-Agent.98304.IX
PandaW32/Autorun.JKS
ZonerTrojan.Win32.123939
TrendMicro-HouseCallWORM_VBNA.SM
RisingTrojan.Autorun!1.DA78 (CLASSIC)
YandexTrojan.GenAsa!Nmq1GgqIrOs
IkarusWorm.Win32.VBNA
FortinetW32/GenericKDZ.70291!tr
AVGWin32:VB-NIK [Wrm]
Cybereasonmalicious.e0d0c5
DeepInstinctMALICIOUS

How to remove Trojan.Win32.VB.bbhv?

Trojan.Win32.VB.bbhv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment