Trojan

Trojan:Win32/Vidar.PBB!MTB malicious file

Malware Removal

The Trojan:Win32/Vidar.PBB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vidar.PBB!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Vidar.PBB!MTB?


File Info:

name: D61FAEA74AEFB72D6668.mlw
path: /opt/CAPEv2/storage/binaries/2fbea17fead08db7829238a6ad03f35e238bdd5b3c6d95201c439b390b97263d
crc32: EE36340D
md5: d61faea74aefb72d6668e6306e97d67d
sha1: 5bc4b14c64198067b1186150d986f90b974b2b1c
sha256: 2fbea17fead08db7829238a6ad03f35e238bdd5b3c6d95201c439b390b97263d
sha512: 38e9053a40f997b2507d5cd178e1d88c0bf905dac1ce42404a8cc7d5817ebdd85cfdf4ef6a65fe23421d9deb4d06320e62b722af079e3ae432bef201a603a8ce
ssdeep: 6144:Kjy+bnr+Sp0yN90QEI0GOzuobmBudwI+ESEiJ1gbfxU2EInhSqVYm0VDQ:tMray90+0mobmCwI+ES5/Axw5m0xQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E684E14BEBEC8022D8B157704DF607D30A37BE515B7883AB374BAD6918725A0A53173B
sha3_384: a6de5c0b1dde3a11b0bf4b78649fa6e83e019b4d99e3dfe9b0670ddef6c21ce34a41fe100eb4aeb8e6dad1758e2dd98b
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

Trojan:Win32/Vidar.PBB!MTB also known as:

LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
ClamAVWin.Packed.Disabler-9987080-0
FireEyeGeneric.mg.d61faea74aefb72d
CAT-QuickHealTrojan.MSIL
McAfeeArtemis!D61FAEA74AEF
VIPRETrojan.GenericKD.65331035
SangforTrojan.Msil.Agent.V972
K7AntiVirusTrojan ( 0059e3df1 )
AlibabaTrojanSpy:Win32/Stealer.c23df1b5
K7GWTrojan ( 0059e3df1 )
Cybereasonmalicious.74aefb
VirITTrojan.Win32.MSIL.EY
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyUDS:Trojan.MSIL.Agent.gen
NANO-AntivirusTrojan.Win32.Disabler.juylrw
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Agent.hg
DrWebTrojan.Siggen19.32857
TrendMicroTROJ_GEN.R002C0PBQ23
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Malicious SFX
GDataWin32.Trojan.Agent.LS4QTT
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Sabsik
MicrosoftTrojan:Win32/Vidar.PBB!MTB
GoogleDetected
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PBQ23
RisingTrojan.Kryptik!1.E349 (CLASSIC:bWQ1Og1hFSx6Nlh97w)
YandexTrojan.Disabler!G6z7qDxyklM
IkarusTrojan.MSIL.Disabler
MaxSecureTrojan.Malware.8703358.susgen
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Chgt.AD

How to remove Trojan:Win32/Vidar.PBB!MTB?

Trojan:Win32/Vidar.PBB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment