Malware

VirTool:Win32/VBInject.NN removal tips

Malware Removal

The VirTool:Win32/VBInject.NN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.NN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine VirTool:Win32/VBInject.NN?


File Info:

name: 26F797A4E94C5EA82E1D.mlw
path: /opt/CAPEv2/storage/binaries/196b0a1e8e54910deff5c07412790994834f1ff61659358aa3034e078e9b1ae5
crc32: F3BBEC4F
md5: 26f797a4e94c5ea82e1d9d971a3d3884
sha1: d8a2c5f50b0f1af64440d9018c730debdd279ced
sha256: 196b0a1e8e54910deff5c07412790994834f1ff61659358aa3034e078e9b1ae5
sha512: 3a2eb5520c4151e635e45d74642eae7136ec6a1bd71733177b74444decb55162e10d8351277a375904cff5f9b0afa6362409701dec0a3d03a365765c834c3bbc
ssdeep: 768:jzXazdeRJoSY10J/m7bb+plAmfVNWHp2iBRMzMkaZE8REEuir2Ad:jezdQogQ+P5NdiBRMgkaZ1yElL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14423D44AEA544BE5D15BE6F100C3E38B4779E041372B194255297B3A7C25E203B2EEBF
sha3_384: dda0affeda50da045377a7dd39a3ed5f08106fbc615beb3116c3e945db708047af140a364a679498c53ff4ed5854d339
ep_bytes: 6878124000e8eeffffff000000000000
timestamp: 2011-01-26 12:51:07

Version Info:

Translation: 0x0409 0x04b0
CompanyName: UserXP
ProductName: NqhgobGYNTk
FileVersion: 1.00
ProductVersion: 1.00
InternalName: xiWaGDJDxqqrQmFwlS
OriginalFilename: xiWaGDJDxqqrQmFwlS.exe

VirTool:Win32/VBInject.NN also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Siggen2.40914
MicroWorld-eScanGen:Variant.Barys.136020
FireEyeGeneric.mg.26f797a4e94c5ea8
SkyhighBehavesLike.Win32.Azero.ph
McAfeeArtemis!26F797A4E94C
VIPREGen:Variant.Barys.136020
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
AlibabaWorm:Win32/Pincav.76f7723c
K7GWTrojan-Downloader ( 001ff72a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.BC38A15C20
VirITTrojan.Win32.Generic.CLGA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Videspra.AF
APEXMalicious
ClamAVWin.Trojan.Agent-758421
KasperskyTrojan.Win32.Pincav.axpq
BitDefenderGen:Variant.Barys.136020
NANO-AntivirusTrojan.Win32.Pincav.iknsp
AvastWin32:Trojan-gen
TencentWin32.Trojan.Pincav.Pjgl
EmsisoftGen:Variant.Barys.136020 (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Pincav.Win32.12769
TrendMicroWORM_VOBFUS.SMIA
Trapminemalicious.high.ml.score
IkarusWorm.Win32.Videspra
GDataGen:Variant.Barys.136020
JiangminTrojan/Pincav.sfw
WebrootW32.Malware.Gen
VaristW32/Trojan.RXZX-1210
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Trojan.Pincav.axpq
XcitiumTrojWare.Win32.Trojan.Vbkrypt.~azy@2oq2in
ArcabitTrojan.Barys.D21354
ViRobotTrojan.Win32.A.Pincav.49152.S
ZoneAlarmTrojan.Win32.Pincav.axpq
MicrosoftVirTool:Win32/VBInject.NN
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.136020
VBA32Trojan.VBRA.04036
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingMalware.Undefined!8.C (TFE:5:IYWm8uBjG1D)
YandexTrojan.GenAsa!4o0U4fnGAMs
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.VOX!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.50b0f1
DeepInstinctMALICIOUS

How to remove VirTool:Win32/VBInject.NN?

VirTool:Win32/VBInject.NN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment