Trojan

What is “Trojan:Win32/VB.VV”?

Malware Removal

The Trojan:Win32/VB.VV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VB.VV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/VB.VV?


File Info:

name: 172CA42452CBF618B1C6.mlw
path: /opt/CAPEv2/storage/binaries/0dd6f590c4308067059f41070731477811fae3cfbee6713c6ab314703654db39
crc32: 1394EC57
md5: 172ca42452cbf618b1c6f307fd930ca1
sha1: aa5680ca81fe473258b773a7c2f5343e1cf79ac1
sha256: 0dd6f590c4308067059f41070731477811fae3cfbee6713c6ab314703654db39
sha512: c0392849d303d85f922023a3e6ef6c3c379a908bbad6376fd2bbdc51ce1d8327055f5edc64da3ecee9656c075a954f307409058308d53c18fa36b957a88ac242
ssdeep: 3072:8kK4XmxsTXKjYKeNvKemKeSKLYKCcikvG3Bk1k3evu:8kK4XgvG3Bok3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11FE37126E614F22BE566C0B5A9D4E667F4156C331410AC1FF7837B9A2571A83B8F032F
sha3_384: 4b7cf44bba518a1e0e2b5773350033dae1f5b99ef8ec63348d061c7b915df737ead2c3610b31b22cd442a0393eaad3f0
ep_bytes: 6808314000e8f0ffffff000000000000
timestamp: 2010-02-03 21:21:28

Version Info:

Translation: 0x0c0a 0x04b0
Comments: Copyright - 2010 ©
CompanyName: MSTECS SAC. SICSA. Diamond Machine Works, Inc. Flash Elecctronics.
FileDescription: Copyright - 2010 ©
LegalCopyright: Copyright - 2010 ©
LegalTrademarks: Copyright - 2010 ©
ProductName: aecces.exe
FileVersion: 1.00
ProductVersion: 1.00
InternalName: aecces
OriginalFilename: aecces.exe

Trojan:Win32/VB.VV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.284691
FireEyeGeneric.mg.172ca42452cbf618
SkyhighGenericRXET-XD!172CA42452CB
ALYacGen:Variant.Johnnie.284691
MalwarebytesMalware.AI.4018097858
ZillyaTrojan.Bancos.Win32.21201
SangforSuspicious.Win32.Save.vb
K7AntiVirusSpyware ( 001117231 )
BitDefenderGen:Variant.Johnnie.284691
K7GWSpyware ( 001117231 )
Cybereasonmalicious.a81fe4
BitDefenderThetaAI:Packer.CA6006CB1E
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Bancos.NOG
APEXMalicious
ClamAVWin.Keylogger.Bancos-9845664-0
KasperskyTrojan-Dropper.Win32.VB.mxr
AlibabaTrojanDropper:Win32/Bancos.8dd3a4be
NANO-AntivirusTrojan.Win32.VB.efwylf
RisingTrojan.VB!8.B20 (TFE:5:cj6DhI7bDLV)
SophosTroj/Bancos-BGR
F-SecureTrojan.TR/VB.vvb
DrWebTrojan.KillFiles.63669
VIPREGen:Variant.Johnnie.284691
TrendMicroTROJ_BANCOS.SMAB
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Johnnie.284691 (B)
IkarusTrojan-Dropper.Win32.VB
JiangminTrojan/PSW.YahuPass.db
WebrootTrojan:Win32/Vb.Vv
GoogleDetected
AviraTR/VB.vvb
Antiy-AVLTrojan[Dropper]/Win32.VB
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/VB.VV
XcitiumMalware@#iofm9p8w73xh
ArcabitTrojan.Johnnie.D45813
ZoneAlarmTrojan-Dropper.Win32.VB.mxr
GDataGen:Variant.Johnnie.284691
CynetMalicious (score: 100)
McAfeeGenericRXET-XD!172CA42452CB
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32OScope.Trojan.VB.01880
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BANCOS.SMAB
TencentWin32.Trojan-Dropper.Vb.Cdhl
YandexTrojan.GenAsa!A6v+eI1MKfw
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBDrpr.AGT!tr
AVGWin32:VB-OKL [Trj]
AvastWin32:VB-OKL [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/VB.VV?

Trojan:Win32/VB.VV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment