Trojan

Trojan:Win32/VBInject.HA!MTB information

Malware Removal

The Trojan:Win32/VBInject.HA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VBInject.HA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/VBInject.HA!MTB?


File Info:

crc32: 446CFFFA
md5: 7116e2ba468273a85a4d06792044514b
name: updates.exe
sha1: 314e32d7831f8e0247dd2fe8c3154177205a3658
sha256: d660907e07f63091aff5c7453f4027546da732160762c54eca26788ab8b5884a
sha512: f3c46470438437eedea130dfb4a3bfbee14521626f6bef4eb0300b8843e23b330ee756a074ddb6983a583a43f54baca502eee8217f9a253bfa53183962915a97
ssdeep: 1536:xKWhuouSmBDB2o2oWcCuInDB23huouSm:+dDBInDBb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: woodruf
FileVersion: 1.00
CompanyName: Piccolosdi
Comments: Noncontuma
ProductName: Burniebeeh
ProductVersion: 1.00
OriginalFilename: woodruf.exe

Trojan:Win32/VBInject.HA!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.42333025
FireEyeTrojan.GenericKD.42333025
McAfeeFareit-FRI!7116E2BA4682
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055fd971 )
BitDefenderTrojan.GenericKD.42333025
K7GWTrojan ( 0055fd971 )
BitDefenderThetaGen:NN.ZevbaCO.34084.em0@auSAO2lb
F-ProtW32/VBInject.ACU.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EKIF
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42333025
KasperskyBackdoor.Win32.NetWiredRC.kfm
AlibabaBackdoor:Win32/NetWiredRC.15e3394b
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.42333025
EmsisoftTrojan.GenericKD.42333025 (B)
F-SecureTrojan.TR/Injector.emuny
DrWebTrojan.DownLoader32.57256
McAfee-GW-EditionBehavesLike.Win32.Trojan.lh
Trapminemalicious.high.ml.score
SophosMal/FareitVB-X
APEXMalicious
CyrenW32/VBInject.ACU.gen!Eldorado
AviraTR/Injector.emuny
ArcabitTrojan.Generic.D285F361
AhnLab-V3Trojan/Win32.VBKrypt.R325365
ZoneAlarmBackdoor.Win32.NetWiredRC.kfm
MicrosoftTrojan:Win32/VBInject.HA!MTB
VBA32BScope.Trojan.Sonbokli
ALYacTrojan.Injector.73728B
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
IkarusTrojan.VB.Crypt
FortinetW32/GenKryptik.EDIS!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan:Win32/VBInject.HA!MTB?

Trojan:Win32/VBInject.HA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment