Malware

VirTool:Win32/VBInject.QG removal tips

Malware Removal

The VirTool:Win32/VBInject.QG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.QG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VirTool:Win32/VBInject.QG?


File Info:

name: 3C322CE036D4103E6120.mlw
path: /opt/CAPEv2/storage/binaries/41da3e481135673afd5c62518917e518ec3fd96032285e74fb694ec280c73ad0
crc32: 41A63A9D
md5: 3c322ce036d4103e61203a6c8d3750b9
sha1: 0bbdee6e744f2ba24806f83271db9015caa4f5cf
sha256: 41da3e481135673afd5c62518917e518ec3fd96032285e74fb694ec280c73ad0
sha512: c488e2924394d3175beadef3d697e704faf673bab1b722a9c11881467d4ff153dc4d0c0537000c21a6960a8472d270da32b696747461c107c38ef532a6c94c0a
ssdeep: 3072:RmN/zOS6TKVkEbuOEvxy/f70G2yVx89wq0vcFUN/NpDDs+OKdDxvDx:U4HTYkEbuOEZy/foG2yVy9kvcC/NpDDB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A504E617F9582121F5870435252A265AB821AD3A1F069E1BF750EFEA79323C3E5F231F
sha3_384: c717aac3930047f90d12aaa6d7f768b0fa670fbfc80a3412b3428f904c8476e0cd66c618c9406a9b91834d590ebc9ec5
ep_bytes: 68ac204000e8eeffffff000000000000
timestamp: 2011-04-28 08:44:47

Version Info:

CompanyName: ICQ, LLC.
FileDescription: ICQ
FileVersion: 7.5.0.5238
InternalName: ICQ
LegalCopyright: Copyright (c) 1998-2010 ICQ, LLC.
LegalTrademarks:
OriginalFilename: ICQ.exe
ProductName: ICQ
ProductVersion: 7.5.0.5238
DistId: 30012
Translation: 0x0409 0x04b0

VirTool:Win32/VBInject.QG also known as:

MicroWorld-eScanGen:Variant.Babar.22778
FireEyeGeneric.mg.3c322ce036d4103e
McAfeePWS-Zbot.gen.hx
CylanceUnsafe
VIPREGen:Variant.Babar.22778
SangforSuspicious.Win32.Save.vb
Cybereasonmalicious.036d41
BitDefenderThetaGen:NN.ZevbaF.34698.lm2@aWwFZ0li
VirITTrojan.Win32.VBCrypt.CCZ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Qhost.NCK
Paloaltogeneric.ml
ClamAVWin.Worm.Vobfus-9812208-0
KasperskyWorm.Win32.WBNA.bspy
BitDefenderGen:Variant.Babar.22778
NANO-AntivirusTrojan.Win32.WBNA.fjfige
CynetMalicious (score: 99)
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Dorkbot-Y [Trj]
TencentWin32.Worm.Wbna.Vmhl
Ad-AwareGen:Variant.Babar.22778
EmsisoftGen:Variant.Babar.22778 (B)
ComodoMalware@#28hn1xduw6qme
DrWebTrojan.VbCrypt.250
ZillyaTrojan.Injector.Win32.149610
McAfee-GW-EditionPWS-Zbot.gen.hx
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
APEXMalicious
WebrootW32.Injector.Gen
AviraTR/Injector.EB.15
Antiy-AVLTrojan/Generic.ASMalwS.7A
MicrosoftVirTool:Win32/VBInject.QG
ViRobotTrojan.Win32.A.VBKrypt.151582.A
ZoneAlarmWorm.Win32.WBNA.bspy
GDataGen:Variant.Babar.22778
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.C106957
VBA32BScope.Trojan.Buzus
ALYacGen:Variant.Babar.22778
MAXmalware (ai score=85)
MalwarebytesMalware.AI.2139736156
RisingHackTool.VBInject!8.1A0 (TFE:5:fhBgW02IPbQ)
IkarusTrojan.Win32.Llac
AVGWin32:Dorkbot-Y [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove VirTool:Win32/VBInject.QG?

VirTool:Win32/VBInject.QG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment