Malware

How to remove “Win32/VB.ONT”?

Malware Removal

The Win32/VB.ONT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.ONT virus can do?

  • Executable code extraction
  • The executable is compressed using UPX

How to determine Win32/VB.ONT?


File Info:

crc32: C6633E47
md5: 47b31b9ea20555f7f44d3d15edb1478a
name: 47B31B9EA20555F7F44D3D15EDB1478A.mlw
sha1: 9a9e6cb7f36ab4c3c58a88db824b983cfdacc2e5
sha256: 2167de86a950d6ac29597002b35bc1aa6cf170d0f6d147d4eaf0dca8456cf389
sha512: c249ed94990f6398df7e5b8d3f7c2431488d6995ceb2956e966820795997a89541cf0af365981737b5314f5db82952d376c43c39b824f7b7f0bffb7f7be6b162
ssdeep: 1536:BzaSN2GXE8AvVu7J+Z0j5oUSqO0bvm+TNSlS:tgLtVu7JAUSGJTyS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: CS_WORM
FileVersion: 1.00
CompanyName: CS.Cheats Corp
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: CS_WORM.exe

Win32/VB.ONT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004bcce41 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.20277
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaWorm.VB.Win32.21392
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaWorm:Win32/Generic.e3597171
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.ea2055
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/VB.ONT
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Dynamer-9847643-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Drop.edfbfr
TencentMalware.Win32.Gencirc.114d841d
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.D5E502171F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUPXAX.lt
FireEyeGeneric.mg.47b31b9ea20555f7
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.241967
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C21
Acronissuspicious
McAfeeArtemis!47B31B9EA205
VBA32Trojan.MulDrop
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!OwmxuoHLXH0
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.UPX!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/VB.ONT?

Win32/VB.ONT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment