Malware

VirTool:Win32/VBInject!GN (file analysis)

Malware Removal

The VirTool:Win32/VBInject!GN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject!GN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Anomalous binary characteristics

How to determine VirTool:Win32/VBInject!GN?


File Info:

name: 63F0B58C9CDE10F4499F.mlw
path: /opt/CAPEv2/storage/binaries/2b53a531f50ae132c3ba692ecc4d9f20d8b0709c23f6edae2c8011150637a283
crc32: AECC7DEE
md5: 63f0b58c9cde10f4499f72f3ad56cdb1
sha1: 74bb5c08a81a851f85bbed28dd998c45e470544c
sha256: 2b53a531f50ae132c3ba692ecc4d9f20d8b0709c23f6edae2c8011150637a283
sha512: 36bfdc666924b590567c4324ad2ee33e0183f5277e3edfed983d1512a9c203aeceb827fbc06770e714e6cc2ad737163334d213853a7423caf4baed75740c8383
ssdeep: 768:xErdTdGfjjLCc+yjnXzL+2gFee5B9WEClWi7bOxu1JtM8cWNgGpRIc:xWTQfjjLH+IyFjc1qxSibCX3J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0632A2FF3967511E1B9BFB06BC2D5C41C2B6EA17A5F11D26908268A0D11F0168C7BBF
sha3_384: 816489c9d9d4aea2abfd9b232de51e7cb5b4f1e8e66bfdc9d037dddfd6b330027c921f39fa2b604d83af7598d011289f
ep_bytes: 68c0124000e8f0ffffff000000000000
timestamp: 2011-06-09 11:22:46

Version Info:

Translation: 0x0407 0x04b0
ProductName: Projekt1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Projekt1
OriginalFilename: Projekt1.exe

VirTool:Win32/VBInject!GN also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.VBKrypt.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.777481
ClamAVWin.Dropper.VertexNet-9962356-0
FireEyeGeneric.mg.63f0b58c9cde10f4
ALYacGen:Variant.Razy.777481
ZillyaTrojan.VBKrypt.Win32.61521
SangforSuspicious.Win32.Save.vb
BitDefenderGen:Variant.Razy.777481
Cybereasonmalicious.c9cde1
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.GYL
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.ywfk
AlibabaWorm:Win32/vobfus.1030
NANO-AntivirusTrojan.Win32.Zbot.fkppdp
RisingMalware.Undefined!8.C (TFE:3:lnB9xfMUY4J)
Ad-AwareGen:Variant.Razy.777481
SophosTroj/FakeAV-DZI
ComodoMalware@#28zb1vsisfe77
DrWebTrojan.PWS.SpySweep.52
VIPREGen:Variant.Razy.777481
TrendMicroTROJ_VBINJ.SMG
McAfee-GW-EditionBehavesLike.Win32.VBObfus.km
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.777481 (B)
IkarusVirus.Win32.VB
JiangminTrojan/Generic.aunco
WebrootW32.Trojan.Vbkrypt.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.32
MicrosoftVirTool:Win32/VBInject.gen!GN
GDataGen:Variant.Razy.777481
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R6239
McAfeePWS-Zbot.gen.gf
MAXmalware (ai score=100)
VBA32TrojanDropper.VB
PandaGeneric Malware
TrendMicro-HouseCallTROJ_VBINJ.SMG
TencentWin32.Trojan-Spy.Zbot.Swhl
YandexTrojan.GenAsa!xk3nLvbZb0A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.GF!tr.pws
BitDefenderThetaAI:Packer.FC961F5E21
AVGWin32:Regrun-GF [Trj]
AvastWin32:Regrun-GF [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove VirTool:Win32/VBInject!GN?

VirTool:Win32/VBInject!GN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment