Trojan

What is “Trojan:Win32/VB.TU”?

Malware Removal

The Trojan:Win32/VB.TU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VB.TU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/VB.TU?


File Info:

name: 203429C434489A540960.mlw
path: /opt/CAPEv2/storage/binaries/69d26d0c4d04d5b7c49be4ae4333a4de5989e01667214d44ccf27f9dac493b54
crc32: 219B3A29
md5: 203429c434489a5409600d812e77a4ca
sha1: 128707c19f2f3f25db44f84b0a8ddca1e32a6600
sha256: 69d26d0c4d04d5b7c49be4ae4333a4de5989e01667214d44ccf27f9dac493b54
sha512: 4ea9c7617e1195e8bae0da971c82e2548f0a925ba1b27a2c15bb186779dfeedd41e2e2b5b0958de2880d2411579d12d28226f72c56c2afacc21b1df40bf59243
ssdeep: 768:NKmfIz1Xq9AJAJAJAJAJAJAJAJAJAJAJAJAJeIsBy6OpY9x0dHXOHk3CCecGH9Cs:NMzgAJAJAJAJAJAJAJAJAJAJAJAJAJe/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11503D83B77041A26ED9E3239365786DB56E3B0CD1F4B0B5736A1237CAC25E902D26B03
sha3_384: 66b564fcd9f497c7862c2f93601375a5ee23d40c4613e41bb7b4b798046c071b058e5b1bbaec0e27341548cb6c043b2d
ep_bytes: 6808124000e8f0ffffff000000000000
timestamp: 2000-01-01 12:00:00

Version Info:

Translation: 0x0409 0x04b0

Trojan:Win32/VB.TU also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li8h
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner.7225
MicroWorld-eScanGen:Trojan.Chinky.2
FireEyeGeneric.mg.203429c434489a54
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.pt
McAfeeGeneric Packed.cn
Cylanceunsafe
ZillyaWorm.VBNA.Win32.37053
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
AlibabaWorm:Win32/Vobfus.5c98026e
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.434489
BitDefenderThetaAI:Packer.8912182520
VirITWorm.Win32.VB.Y
SymantecW32.SillyFDC.BDH
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.FB
APEXMalicious
TrendMicro-HouseCallWORM_VB.SMP
ClamAVWin.Trojan.Chinky-1
KasperskyWorm.Win32.Vobfus.exha
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.VB.bdlzl
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
AvastWin32:VB-NIK [Wrm]
EmsisoftGen:Trojan.Chinky.2 (B)
F-SecureTrojan.TR/VB.bjd.2
BaiduWin32.Worm.VB.nf
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VB.SMP
Trapminesuspicious.low.ml.score
SophosW32/SillyFDC-DS
IkarusVirus.Win32.AutoRun
JiangminWorm/VBNA.gzbq
GoogleDetected
AviraTR/VB.bjd.2
VaristW32/VB.W.gen!Eldorado
Antiy-AVLWorm/Win32.VBNA.a
KingsoftWin32.Worm.Vobfus.exha
MicrosoftTrojan:Win32/VB.TU
XcitiumTrojWare.Win32.Trojan.VB.tqu0@1cd4gg
ArcabitTrojan.Chinky.2
ViRobotWorm.Win32.A.VBNA.40960.NX
ZoneAlarmWorm.Win32.Vobfus.exha
GDataGen:Trojan.Chinky.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Chinky.Gen
Acronissuspicious
VBA32Worm.Vobfus
ALYacGen:Trojan.Chinky.2
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.gen.worm
RisingWorm.Win32.VB.xi (CLASSIC)
YandexTrojan.GenAsa!NCN7rMc348E
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:VB-NIK [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/VB.TU?

Trojan:Win32/VB.TU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment