Malware

VirTool:Win32/VBInject.SD (file analysis)

Malware Removal

The VirTool:Win32/VBInject.SD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.SD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Icelandic
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/VBInject.SD?


File Info:

crc32: 1453E1C0
md5: b82730e1486c43483ad55a0df2c3da7b
name: B82730E1486C43483AD55A0DF2C3DA7B.mlw
sha1: 07462ce15c87abed06fc5879382a22c61111f701
sha256: dd6c4db7d170a7e7f591b6f8f145c5b689105e4498cc373e16ba28c4ab827065
sha512: 89ce4fe8c4f3035fd86ab8f53902f675a3b73157bea255296baffe7e423b410cfa191fb72f687200f28bbfbb69eec01b3a47c8a9b56ab6cfec5e2ae56a8e5e24
ssdeep: 3072:7D+u1j5lyeral7uYTy0ZKsFod6tFACBpwd3:n+uh+uY2iRFoYtF5B0
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: License: MPL 1.1/GPL 2.0/LGPL 2.1
InternalName: crashreporter
FileVersion: 1.9.2.18
CompanyName: Mozilla Foundation
BuildID: 20110614230723
LegalTrademarks: Mozilla
Comments:
ProductName: Firefox
ProductVersion: 1.9.2.18
FileDescription:
OriginalFilename: crashreporter.exe
Translation: 0x0000 0x04b0

VirTool:Win32/VBInject.SD also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.6636261
FireEyeGeneric.mg.b82730e1486c4348
CAT-QuickHealTrojan.VBCrypt.MF.2915
McAfeePWS-Zbot.gen.awf
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.95175
K7AntiVirusRiskware ( 000027db1 )
BitDefenderTrojan.Generic.6636261
K7GWRiskware ( 000027db1 )
Cybereasonmalicious.1486c4
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:GenMalicious-LVX [Trj]
ClamAVWin.Trojan.Vbkrypt-22217
KasperskyTrojan.Win32.VBKrypt.ereo
NANO-AntivirusTrojan.Win32.VBKrypt.eeraml
ViRobotTrojan.Win32.A.VBKrypt.122508.A
Ad-AwareTrojan.Generic.6636261
EmsisoftTrojan.Generic.6636261 (B)
ComodoMalware@#2ziimajbh4cv
F-SecureTrojan.TR/Crypt.PEPM.Gen
DrWebTrojan.PWS.Panda.368
VIPRELooksLike.Win32.Malware!vb (v)
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
SophosML/PE-A + Mal/SwiftG-K
SentinelOneStatic AI – Suspicious PE
JiangminWorm/Kolab.fyb
AviraTR/Crypt.PEPM.Gen
MAXmalware (ai score=87)
MicrosoftVirTool:Win32/VBInject.SD
ArcabitTrojan.Generic.D6542E5
ZoneAlarmTrojan.Win32.VBKrypt.ereo
GDataTrojan.Generic.6636261
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.C69553
ALYacTrojan.Generic.6636261
MalwarebytesMalware.Heuristic.1001
PandaTrj/Genetic.gen
ESET-NOD32Win32/Spy.Zbot.YW
YandexTrojan.VBKrypt!mBMJk4zqA6k
IkarusTrojan.Win32.Spyeye
FortinetW32/VBKrypt.EREO!tr
BitDefenderThetaGen:NN.ZevbaF.34804.hi1aamWwBBmO
AVGWin32:GenMalicious-LVX [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.bc4

How to remove VirTool:Win32/VBInject.SD?

VirTool:Win32/VBInject.SD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment