Virus

Virus:Win32/VB.AN removal instruction

Malware Removal

The Virus:Win32/VB.AN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/VB.AN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Installs a browser addon or extension
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/VB.AN?


File Info:

name: BE8827F11474F9B8F3CF.mlw
path: /opt/CAPEv2/storage/binaries/37ba8192f739f90f3620a8a857519a389dd241b702f65b2ba747ae64e1ca4300
crc32: AC05F05E
md5: be8827f11474f9b8f3cf8f8d6780e615
sha1: 1a34c50ab88fd285d9ec4885ef12919f9ab7847f
sha256: 37ba8192f739f90f3620a8a857519a389dd241b702f65b2ba747ae64e1ca4300
sha512: ae388cee246080c7cfa5bb3c718faa44b51978d9201c392451a55cd90fb1682bf1437184679cf8d0a607585b3bdd84a20de3ca225b66ae5c0ce0df79d3b687c9
ssdeep: 768:DW4wnebSdDlmkok6lRGXu+jKZAOWjpiRHVAGr4PzpyRAJ7IwnDoSdO:lbC4Bk6lMTOWw4PkRAPoz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103B3E84BF25281B9CA38C537A561C2B21F253D75AA63CA3F31513A2B2D75B001E1AF37
sha3_384: d0ab331879dea1e91e8a948d80d54605abb885b49dc89018d4c5618658ad1c040f09f3c4492475725e74b40d12810e76
ep_bytes: 68a0774000e8f0ffffff000000000000
timestamp: 2006-02-15 09:09:50

Version Info:

0: [No Data]

Virus:Win32/VB.AN also known as:

BkavW32.AIDetectMalware
DrWebWin32.HLLW.Pacar
MicroWorld-eScanTrojan.GenericKD.66334657
McAfeeGeneric VB.do
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.66334657
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059441b1 )
BitDefenderTrojan.GenericKD.66334657
K7GWTrojan ( 0059441b1 )
Cybereasonmalicious.11474f
ArcabitTrojan.Generic.D3F42FC1
BitDefenderThetaAI:Packer.27A424791D
CyrenW32/VBTrojan.17E!Maximus
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.AN
APEXMalicious
ClamAVWin.Trojan.Pacar-1
KasperskyVirus.Win32.VB.an
AlibabaWorm:Win32/vobfus.1030
NANO-AntivirusVirus.Win32.VB.lqxov
AvastWin32:VB-HMJ
RisingTrojan.Mirip!1.692D (CLASSIC)
EmsisoftTrojan.GenericKD.66334657 (B)
F-SecureMalware.W32/VB.AN.1
ZillyaVirus.VB.Win32.12
TrendMicroWORM_VB.ARL
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.be8827f11474f9b8
SophosMal/VB-F
IkarusWorm.Win32.VBNA
JiangminTrojan/VB.Small.ki
GoogleDetected
AviraW32/VB.AN.1
Antiy-AVLVirus/Win32.VB.an
XcitiumWin32.VB.AN@403j
MicrosoftVirus:Win32/VB.AN
ZoneAlarmVirus.Win32.VB.an
GDataTrojan.GenericKD.66334657
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.C27345
Acronissuspicious
VBA32Virus.Win32.VB.an
ALYacTrojan.GenericKD.66334657
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VB.ARL
TencentWin32.Virus.Vb.Fdhl
YandexTrojan.GenAsa!KUbF8ei+G18
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Pirim.AN!tr
AVGWin32:VB-HMJ
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/VB.AN?

Virus:Win32/VB.AN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment