Malware

How to remove “VirTool:Win32/VBInject!BG”?

Malware Removal

The VirTool:Win32/VBInject!BG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject!BG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Deletes executed files from disk
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Attempts to masquerade or mimic a legitimate process or file name
  • Uses suspicious command line tools or Windows utilities

How to determine VirTool:Win32/VBInject!BG?


File Info:

name: 17FC9D892054F212A337.mlw
path: /opt/CAPEv2/storage/binaries/7ed7033939b8cc2c3b51be25af2cbbb57cfea5361ffc8ca05f208e30d9a761db
crc32: E7E5B7A5
md5: 17fc9d892054f212a3372fd8ed887252
sha1: b107490fd4bfef77d8efc006204d0344d8c2216a
sha256: 7ed7033939b8cc2c3b51be25af2cbbb57cfea5361ffc8ca05f208e30d9a761db
sha512: a75d23047b1eb5a449e523dde10c98b03a5497a031c3d7213260bbd0a03f39dad17d0cb5bfa04351c0b91dd84389adaa927dad5cccc0176127af32fa8827a3b1
ssdeep: 6144:t9lRtBw24OnsNPULuTygi+oXLgCo2o5OBxwb6l3QQEzMnlUOalWKeQN2NtQfP0Ox:f1B7SULoyRBtcaQhRlWKeDNt8PnRP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC94D02D6AFC2133D0AAC6F59BC69967F02AE53632651C26D5CA93489787D43318333F
sha3_384: 6cd046b855bd68946a4926a12ea44ed908eea35a46c47a3e72047de4927f093d6955c71a3cde64a77dcb7c449ea88aa4
ep_bytes: 68c0164000e8eeffffff000000000000
timestamp: 2009-06-20 06:11:25

Version Info:

CompanyName: Sunbelt Software
FileDescription: Setup Launcher
FileVersion: 2.5.1042.0
InternalName: Setup
LegalCopyright: Copyright (C) 2006 Macrovision Corporation
OriginalFilename: Setup.exe
ProductName: Sunbelt CounterSpy
ProductVersion: 2.5.1042.0
OLESelfRegister:
Translation: 0x0409 0x04b0

VirTool:Win32/VBInject!BG also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.VB.l4bq
MicroWorld-eScanGen:Heur.VB.Krypt.10
FireEyeGeneric.mg.17fc9d892054f212
ALYacGen:Heur.VB.Krypt.10
CylanceUnsafe
VIPREGen:Heur.VB.Krypt.10
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaTrojan:Win32/Buzus.5c19d418
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.92054f
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.QJ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Buzus.bzqe
BitDefenderGen:Heur.VB.Krypt.10
NANO-AntivirusTrojan.Win32.Buzus.ngmez
AvastWin32:GenMalicious-JAG [Trj]
TencentWin32.Trojan.Buzus.Bujl
Ad-AwareGen:Heur.VB.Krypt.10
EmsisoftGen:Heur.VB.Krypt.10 (B)
ComodoTrojWare.Win32.VBInject.IK@1qsu2f
DrWebBackDoor.Bifrost.8
ZillyaTrojan.Buzus.Win32.53561
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosML/PE-A + Mal/VB-AD
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VB.Krypt.10
JiangminTrojan.Buzus.sq
WebrootVir.Tool.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.AA
KingsoftWin32.Troj.Generic.a.(kcloud)
ViRobotTrojan.Win32.A.Buzus.100000.J
MicrosoftVirTool:Win32/VBInject.gen!BG
GoogleDetected
AhnLab-V3Trojan/Win32.Buzus.R35308
Acronissuspicious
McAfeeW32/Hamweq.worm.aq
MAXmalware (ai score=100)
VBA32BScope.TrojanSpy.Zbot
RisingHackTool.VBInject!8.1A0 (TFE:4:OCakcpjv2PJ)
YandexTrojan.GenAsa!Dp6P0VR43To
IkarusVirTool.Win32.VBInject
MaxSecureTrojan.Malware.617905.susgen
FortinetW32/VBInjector.W!tr
BitDefenderThetaGen:NN.ZevbaF.34682.Am1@a4kDVqdi
AVGWin32:GenMalicious-JAG [Trj]
PandaAdware/AccesMembre
CrowdStrikewin/malicious_confidence_100% (W)

How to remove VirTool:Win32/VBInject!BG?

VirTool:Win32/VBInject!BG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment