Trojan

How to remove “Trojan:Win32/VB.YT”?

Malware Removal

The Trojan:Win32/VB.YT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VB.YT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/VB.YT?


File Info:

name: 9C0541AA1923CD9E2B19.mlw
path: /opt/CAPEv2/storage/binaries/19b54178a9e755bb8e621154314bfbab53a33125d342cc8364d94c6550a57ee3
crc32: 64B2B3E6
md5: 9c0541aa1923cd9e2b19a23a2d477ee8
sha1: f5329308c2eeaaa31613d2967c4f968656596194
sha256: 19b54178a9e755bb8e621154314bfbab53a33125d342cc8364d94c6550a57ee3
sha512: 78eca1dcf02eae4753fcd04411c7de88b4bf5cc09d250d3b382c45046a29682584f82fa67095e9901df766ca63feb2ebadffee6de2588781018d70b027e731c6
ssdeep: 768:up6Y7XyQ1FmZ4bOeiZztGanY/kgzP/RNw68PTt/anaVGyyXyQ6BCbkSXyQW:D4b0AYiDw68Pga9dhR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18993F837EA406563F1A186B00873C1B5FA13BD350A978E476686BF691D31A03BDE532F
sha3_384: 95ca030e744cada8f3055903555a16ec53a1b55b0effe1e499c6417eb54f0717f37f12a991d423637b96c701dff5c8d7
ep_bytes: 68302c4000e8eeffffff000000000000
timestamp: 2014-03-10 07:51:28

Version Info:

Translation: 0x0409 0x04b0
CompanyName: SYNBOZ ©
ProductName: VINACF
FileVersion: 0.01.0001
ProductVersion: 0.01.0001
InternalName: 1.3
OriginalFilename: 1.3.exe

Trojan:Win32/VB.YT also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lIxN
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.529
FireEyeGeneric.mg.9c0541aa1923cd9e
CAT-QuickHealTrojan.VBCrypt.MF.123
SkyhighPWS-LDPinch.gen.a
McAfeeGenericRXAA-AA!9C0541AA1923
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Symmi.529
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan-Downloader ( 004d7c5b1 )
BitDefenderGen:Variant.Symmi.529
K7GWTrojan-Downloader ( 004d7c5b1 )
Cybereasonmalicious.8c2eea
BitDefenderThetaGen:NN.ZevbaF.36792.fm0@aSVnGDbi
VirITTrojan.Win32.Inject.CHI
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.VB.QMT
APEXMalicious
KasperskyWorm.Win32.VBNA.bsev
AlibabaWorm:Win32/Inject.cdf7d595
NANO-AntivirusTrojan.Win32.VB.dxkvlh
RisingMalware.Undefined!8.C (TFE:5:CXX7PMa0r9I)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Crypt.54
ZillyaWorm.VBNA.Win32.179459
TrendMicroMal_VBInj1
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Symmi.529 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.VBNA
MicrosoftTrojan:Win32/VB.YT
XcitiumTrojWare.Win32.Injector.KRTE@57zc23
ArcabitTrojan.Symmi.529
ZoneAlarmWorm.Win32.VBNA.bsev
GDataGen:Variant.Symmi.529
CynetMalicious (score: 99)
AhnLab-V3Worm/Win32.VBNA.C256815
VBA32Trojan.VB.Motil
ALYacGen:Variant.Symmi.529
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallMal_VBInj1
TencentMalware.Win32.Gencirc.11494674
YandexTrojan.VBInject.Gen.7
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.BEG!tr
AVGWin32:Bifrose-FAH [Trj]
AvastWin32:Bifrose-FAH [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/VB.YT?

Trojan:Win32/VB.YT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment