Trojan

Trojan:Win32/VB.ABN removal guide

Malware Removal

The Trojan:Win32/VB.ABN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VB.ABN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/VB.ABN?


File Info:

name: 71A384CFEC9927ED5165.mlw
path: /opt/CAPEv2/storage/binaries/ea884f3665ce52ff45cac26c973cc394928d83b70054e64fb8f39c990525286c
crc32: F7BDDFA3
md5: 71a384cfec9927ed5165c31d3bbb0842
sha1: 41f2d4cfc2f16fe221e6ce367240204486e71650
sha256: ea884f3665ce52ff45cac26c973cc394928d83b70054e64fb8f39c990525286c
sha512: 2d910608b9a807fb6ec67b02bdc5df8b8f7ceb4b8bf15d05ab339f5987d0c070d35428604fa07b6449a97f425ed53b345df3473bf726c1f812450bbe9ef13f30
ssdeep: 1536:ncNP4OgbJZlCc/Tt+WrEyWt1RtJTG8GvYu5U/U5Io+Yy:cSrZ8gTt+WNvYqU85Vq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12EA39417FA60A61EF45380B02A34A1973D667E3648509D4BB741EF8929726C3F4F6B0F
sha3_384: d24dc22542c42fbe6f2fd31ce0d1d0b6cd88cf85c58048fba0db2f327876eadec06e0acd25b500beaeb82d56f4a5d577
ep_bytes: 680c2e4000e8f0ffffff000000000000
timestamp: 2010-03-11 07:40:17

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 番茄花园
ProductName: 工程1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ALITB2
OriginalFilename: ALITB2.exe

Trojan:Win32/VB.ABN also known as:

LionicTrojan.Win32.Psyk.i!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Jaik.121473
FireEyeGeneric.mg.71a384cfec9927ed
SkyhighBehavesLike.Win32.Infected.cm
McAfeeArtemis!71A384CFEC99
Cylanceunsafe
ZillyaTrojan.Psyk.Win32.38
SangforTrojan.VBS.Agent.STX
K7AntiVirusTrojan-Downloader ( 005684af1 )
AlibabaTrojanPSW:Win32/ATRAPS.157de188
K7GWTrojan-Downloader ( 005684af1 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Jaik.D1DA81
BitDefenderThetaGen:NN.ZevbaF.36744.gm0@aeFHE7fb
VirITTrojan.Win32.Generic.URB
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/VB.STX
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Generic-10015153-0
KasperskyTrojan-PSW.Win32.Psyk.ag
BitDefenderGen:Variant.Jaik.121473
NANO-AntivirusTrojan.Win32.Psyk.hvtax
AvastWin32:Malware-gen
TencentWin32.Trojan-QQPass.QQRob.Bwnw
EmsisoftGen:Variant.Jaik.121473 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.PWS.Siggen.8884
VIPREGen:Variant.Jaik.121473
TrendMicroTROJ_VB.SMIU
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen
KingsoftWin32.Troj.Unknown.a
XcitiumMalware@#2c8quhzqz14nc
MicrosoftTrojan:Win32/VB.ABN
ZoneAlarmTrojan-PSW.Win32.Psyk.ag
GDataGen:Variant.Jaik.121473
ALYacGen:Variant.Jaik.121473
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
TrendMicro-HouseCallTROJ_VB.SMIU
RisingTrojan.DL.Win32.VBcode.alr (CLASSIC)
YandexTrojan.GenAsa!BUW8RoG4Ikg
IkarusTrojan-PWS.Win32.Agent
MaxSecureTrojan.Malware.4244796.susgen
FortinetW32/Psyk.AG!tr.pws
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/VB.ABN?

Trojan:Win32/VB.ABN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment