Categories: Malware

VirTool:Win32/VBInject.SD (file analysis)

The VirTool:Win32/VBInject.SD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.SD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Icelandic
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/VBInject.SD?


File Info:

crc32: 1453E1C0md5: b82730e1486c43483ad55a0df2c3da7bname: B82730E1486C43483AD55A0DF2C3DA7B.mlwsha1: 07462ce15c87abed06fc5879382a22c61111f701sha256: dd6c4db7d170a7e7f591b6f8f145c5b689105e4498cc373e16ba28c4ab827065sha512: 89ce4fe8c4f3035fd86ab8f53902f675a3b73157bea255296baffe7e423b410cfa191fb72f687200f28bbfbb69eec01b3a47c8a9b56ab6cfec5e2ae56a8e5e24ssdeep: 3072:7D+u1j5lyeral7uYTy0ZKsFod6tFACBpwd3:n+uh+uY2iRFoYtF5B0type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: License: MPL 1.1/GPL 2.0/LGPL 2.1InternalName: crashreporterFileVersion: 1.9.2.18CompanyName: Mozilla FoundationBuildID: 20110614230723LegalTrademarks: MozillaComments: ProductName: FirefoxProductVersion: 1.9.2.18FileDescription: OriginalFilename: crashreporter.exeTranslation: 0x0000 0x04b0

VirTool:Win32/VBInject.SD also known as:

Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Generic.6636261
FireEye Generic.mg.b82730e1486c4348
CAT-QuickHeal Trojan.VBCrypt.MF.2915
McAfee PWS-Zbot.gen.awf
Cylance Unsafe
Zillya Trojan.VBKrypt.Win32.95175
K7AntiVirus Riskware ( 000027db1 )
BitDefender Trojan.Generic.6636261
K7GW Riskware ( 000027db1 )
Cybereason malicious.1486c4
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:GenMalicious-LVX [Trj]
ClamAV Win.Trojan.Vbkrypt-22217
Kaspersky Trojan.Win32.VBKrypt.ereo
NANO-Antivirus Trojan.Win32.VBKrypt.eeraml
ViRobot Trojan.Win32.A.VBKrypt.122508.A
Ad-Aware Trojan.Generic.6636261
Emsisoft Trojan.Generic.6636261 (B)
Comodo Malware@#2ziimajbh4cv
F-Secure Trojan.TR/Crypt.PEPM.Gen
DrWeb Trojan.PWS.Panda.368
VIPRE LooksLike.Win32.Malware!vb (v)
McAfee-GW-Edition BehavesLike.Win32.Trojan.cc
Sophos ML/PE-A + Mal/SwiftG-K
SentinelOne Static AI – Suspicious PE
Jiangmin Worm/Kolab.fyb
Avira TR/Crypt.PEPM.Gen
MAX malware (ai score=87)
Microsoft VirTool:Win32/VBInject.SD
Arcabit Trojan.Generic.D6542E5
ZoneAlarm Trojan.Win32.VBKrypt.ereo
GData Trojan.Generic.6636261
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.VBKrypt.C69553
ALYac Trojan.Generic.6636261
Malwarebytes Malware.Heuristic.1001
Panda Trj/Genetic.gen
ESET-NOD32 Win32/Spy.Zbot.YW
Yandex Trojan.VBKrypt!mBMJk4zqA6k
Ikarus Trojan.Win32.Spyeye
Fortinet W32/VBKrypt.EREO!tr
BitDefenderTheta Gen:NN.ZevbaF.34804.hi1aamWwBBmO
AVG Win32:GenMalicious-LVX [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 Win32/Trojan.bc4

How to remove VirTool:Win32/VBInject.SD?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago