Malware

Should I remove “Win32/VB.OSK”?

Malware Removal

The Win32/VB.OSK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.OSK virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/VB.OSK?


File Info:

crc32: 65DF0396
md5: 4a76c8088a200eaa6b6aecd5e7d7730c
name: kragerne11.exe
sha1: 8bf3694dddfd69d919cbe82967ea36d8454ff614
sha256: c5810cc4410105bcc1d150758117307f9b49adcb21d1bef6ac97bb1215007e72
sha512: f4c9e76bd8086706035cf9eb1a81ae3a06445cc89f184529748e99e901b21d6ae8374cadf2c27eda66b279009e561e55c90a7eec43b57574ba53843d6507ab56
ssdeep: 3072:CvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6un1iyc+:CvEN2U+T6i5LirrllHy4HUcMQY6c
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Win
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Win
ProductVersion: 1.00
OriginalFilename: Win.exe

Win32/VB.OSK also known as:

BkavW32.VBOverlayD.PE
MicroWorld-eScanTrojan.GenericKD.31842094
FireEyeGeneric.mg.4a76c8088a200eaa
CAT-QuickHealTrojan.Mofksys.A
Qihoo-360HEUR/QVM03.0.4281.Malware.Gen
McAfeeW32/Swisyn.ag
MalwarebytesTrojan.VBCrypt
VIPRETrojan-PWS.Win32.VB.cu (v)
K7AntiVirusTrojan ( 0040f0591 )
BitDefenderTrojan.GenericKD.31842094
K7GWTrojan ( 0040f0591 )
Cybereasonmalicious.88a200
Invinceaheuristic
BaiduWin32.Trojan.VB.at
F-ProtW32/VB.AD.gen!Eldorado
SymantecW32.Gosys
TotalDefenseWin32/VB.BOP
APEXMalicious
AvastWin32:VB-AJKP [Trj]
ClamAVWin.Virus.Sality:1-6335700-1
GDataTrojan.GenericKD.31842094
KasperskyTrojan.Win32.Swisyn.bner
NANO-AntivirusTrojan.Win32.Swisyn.efyboj
TencentTrojan.Win32.Swisyn.f
Endgamemalicious (high confidence)
SophosTroj/VB-JVT
ComodoTrojWare.Win32.VB.OSKB@4pc2ok
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.Siggen6.54687
ZillyaTrojan.Swisyn.Win32.32298
TrendMicroPE_MOFKSYS.A
McAfee-GW-EditionBehavesLike.Win32.Swisyn.dm
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Swisyn!O
EmsisoftTrojan.GenericKD.31842094 (B)
SentinelOneDFI – Malicious PE
CyrenW32/VB.AD.gen!Eldorado
JiangminTrojan/Swisyn.rmj
WebrootW32.Trojan.Gen
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Swisyn.bner
ArcabitTrojan.Generic.D1E5DF2E
ZoneAlarmTrojan.Win32.Swisyn.bner
MicrosoftPWS:Win32/VB.CU
AhnLab-V3Trojan/Win32.Swisyn.R1452
Acronissuspicious
VBA32MAS.Trojan.VB.01049
ALYacTrojan.GenericKD.31842094
Ad-AwareTrojan.GenericKD.31842094
CylanceUnsafe
PandaGeneric Malware
ZonerTrojan.Win32.47063
ESET-NOD32Win32/VB.OSK
TrendMicro-HouseCallPE_MOFKSYS.A
RisingTrojan.QOT!1.6519 (CLASSIC)
YandexTrojan.VBGent.Gen.471
MAXmalware (ai score=85)
FortinetW32/Swisyn.BNER!tr
BitDefenderThetaAI:Packer.F21A242320
AVGWin32:VB-AJKP [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Swisyn.BNER

How to remove Win32/VB.OSK?

Win32/VB.OSK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment