Virus

Virus:Win32/VB.BT information

Malware Removal

The Virus:Win32/VB.BT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/VB.BT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Virus:Win32/VB.BT?


File Info:

name: 5A5A5FEDF8A8C0BF7507.mlw
path: /opt/CAPEv2/storage/binaries/5a524bb5e348f6c9b74f04d0cc26008ca472f6533f2a07d9a0d1b8c11a3da64c
crc32: F258D0B7
md5: 5a5a5fedf8a8c0bf75070a632010faa9
sha1: f16c0e957a4f52d229670ab469c658946a688671
sha256: 5a524bb5e348f6c9b74f04d0cc26008ca472f6533f2a07d9a0d1b8c11a3da64c
sha512: df260f3ea2ce10034689c8e87414c73e26bf7fc13fccc2c89ab8bcdf76d4053b8f22232a6cd7b669f1d0983841ff0ac67a0eb33be131dbbc5fc9d24c69478c1e
ssdeep: 24576:7Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd8Pd:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7754902B714D5E6F1244BB15827B2D96995BC3249807A732294BF2A3C722D3B176F3F
sha3_384: 23d5ca81f361042efb91012c769fe51fabfb3da79519c6456c3194e1b868b58b48f7d9c0f928c970c6977f54465560aa
ep_bytes: 68608d4000e8eeffffff000000000000
timestamp: 2005-11-16 17:58:46

Version Info:

Translation: 0x0c0a 0x04b0
CompanyName: GETZAC
ProductName: contenedor
FileVersion: 1.00
ProductVersion: 1.00
InternalName: contenedor
OriginalFilename: contenedor.exe

Virus:Win32/VB.BT also known as:

LionicVirus.Win32.VB.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Contenedor.A
FireEyeGeneric.mg.5a5a5fedf8a8c0bf
ALYacTrojan.Contenedor.A
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaVirus:Win32/Generic.24b8c74d
Cybereasonmalicious.df8a8c
CyrenW32/VB.VB.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/VB.BT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Contenedor-9853452-0
KasperskyVirus.Win32.VB.bt
BitDefenderTrojan.Contenedor.A
NANO-AntivirusTrojan.Win32.VB.bqgdv
AvastWin32:Malware-gen
RisingWorm.VB.hj (CLASSIC)
Ad-AwareTrojan.Contenedor.A
SophosMal/Generic-S
ComodoWin32.VB.BT@w3n
TrendMicroTROJ_GEN.R002C0CL221
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tt
EmsisoftTrojan.Contenedor.A (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Contenedor.A
AviraTR/Dropper.Gen
MicrosoftVirus:Win32/VB.BT
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.C2056004
McAfeeW32/Generic.q
MAXmalware (ai score=88)
VBA32Trojan.VBRA.083
TrendMicro-HouseCallTROJ_GEN.R002C0CL221
TencentWin32.Virus.Vb.Swle
IkarusVirus.Win32.VB
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
BitDefenderThetaAI:Packer.2FC1744C1F
AVGWin32:Malware-gen
PandaW32/VB.PC.worm
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Virus:Win32/VB.BT?

Virus:Win32/VB.BT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment