Trojan

Trojan:Win32/VBObfuse.BBI!MTB (file analysis)

Malware Removal

The Trojan:Win32/VBObfuse.BBI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VBObfuse.BBI!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:Win32/VBObfuse.BBI!MTB?


File Info:

name: 662641B794E65B115419.mlw
path: /opt/CAPEv2/storage/binaries/667626c264be254cb7024622e57d65f64456b14bd3d585a4c6a3ba8895ecf567
crc32: 81ADF1A7
md5: 662641b794e65b115419ca4bd9aab7f5
sha1: b705b8614f151bb2b4320f25957a163777b06108
sha256: 667626c264be254cb7024622e57d65f64456b14bd3d585a4c6a3ba8895ecf567
sha512: b25e0fc4e31b49c75290aff844aeea195df94ec7bf8ccdb13151146130ea67f58c9ac2ed722cbcba860adcbbc800e4712985f542d45e377deb81d79756574671
ssdeep: 3072:tFHmuZJvNPtk1BMl2L4+FI72wTV19TqRG9ELrnP:tRmuZJByjMl2U59+lL7P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185E3F99132C4D99ED4A8D9BD2FD1C16584BC7DB84C9323173AEC330A1DB658CE6A13A7
sha3_384: 0b0cc3c1dbea6ced88aac58904420bac1df27d53c7cf31fb0c8a6d6d26dd36bb08f8531bcfc6a611b4605e33946273a0
ep_bytes: 68f0ff4000e8f0ffffff000000000000
timestamp: 2016-07-11 23:49:32

Version Info:

Translation: 0x0409 0x04b0
Comments: Yellowsva.com
CompanyName: Yellowsva.com
FileDescription: Yellowsva.com
LegalCopyright: Yellowsva.com
LegalTrademarks: Yellowsva.com
ProductName: Yellowsva.com
FileVersion: 4.00
ProductVersion: 4.00
InternalName: crosshand
OriginalFilename: crosshand.exe

Trojan:Win32/VBObfuse.BBI!MTB also known as:

LionicWorm.Win32.WBVB.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doris.10695
ALYacGen:Variant.Doris.10695
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.111484
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/VBObfuse.08067793
K7GWTrojan ( 0058a2131 )
K7AntiVirusTrojan ( 0058a2131 )
CyrenW32/VBKrypt.BCX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FNFA
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Worm.Win32.WBVB
BitDefenderGen:Variant.Doris.10695
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Doris.10695
SophosMal/Generic-R + Troj/Zbot-POJ
TrendMicroTROJ_GEN.R002C0DKA21
McAfee-GW-EditionRDN/Generic.dx
FireEyeGeneric.mg.662641b794e65b11
EmsisoftGen:Variant.Doris.10695 (B)
IkarusTrojan.Win32.Krypt
GDataGen:Variant.Doris.10695
AviraTR/AD.Nekark.illbr
ViRobotTrojan.Win32.Z.Genkryptik.144456
MicrosoftTrojan:Win32/VBObfuse.BBI!MTB
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.VBObfuse.R449595
McAfeeRDN/Generic.dx
MAXmalware (ai score=85)
VBA32BScope.Worm.WBVB
MalwarebytesTrojan.GuLoader.VB
TrendMicro-HouseCallTROJ_GEN.R002C0DKA21
YandexTrojan.Igent.bWUKkW.24
eGambitUnsafe.AI_Score_97%
FortinetW32/GenKryptik.FNFA!tr
BitDefenderThetaGen:NN.ZevbaF.34084.im1@a0S8mWci
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/VBObfuse.BBI!MTB?

Trojan:Win32/VBObfuse.BBI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment