Malware

What is “Win32/VB.PEU”?

Malware Removal

The Win32/VB.PEU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.PEU virus can do?

  • Executable code extraction
  • Anomalous binary characteristics

How to determine Win32/VB.PEU?


File Info:

crc32: EA3F16F3
md5: 99af4e5f4204214580a249ab8855184d
name: 99AF4E5F4204214580A249AB8855184D.mlw
sha1: 73f2b3a056046faa12ba6bf4f0f33c5d75b10251
sha256: 51e58624d6fc46b6d5ee5546251c07b533c73689bb1b60a256c1d2a9b0a4a434
sha512: 4e7c30f4d78247ecd8ef061d3e9de5658f67b0296e367b9859184bfb910902a8c40f445017844d7f5e8528c8f96fbdcbb9e3d5d50b9517d0497e1e6aa4578cb3
ssdeep: 3072:XMs3fGBjN1Jrpi0kOBzleK6VU6SaQFQMg6W:Xn3MN1JlveK6VUsQOj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: essai
FileVersion: 15.05.0088
ProductName: xcv
ProductVersion: 15.05.0088
FileDescription: Dossier de fichiers
OriginalFilename: essai.exe

Win32/VB.PEU also known as:

BkavW32.FamVT.TroaraN.Trojan
Elasticmalicious (high confidence)
ClamAVWin.Trojan.VBGeneric-6735767-0
FireEyeGeneric.mg.99af4e5f42042145
CAT-QuickHealTrojan.Comisproc.AZ3
Qihoo-360Win32/Worm.FakeFolder.KI
McAfeeW32/Autorun.worm.qb
CylanceUnsafe
ZillyaTrojan.VB.Win32.56251
SUPERAntiSpywareTrojan.Agent/Gen-Comisproc
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005640b91 )
AlibabaWorm:Win32/Mofksys.ffc9d735
K7GWTrojan ( 005640b91 )
Cybereasonmalicious.f42042
BaiduWin32.Trojan.VB.je
CyrenW32/Trojan.LOQB-2066
SymantecTrojan Horse
TotalDefenseWin32/VB.BVC
APEXMalicious
AvastWin32:Patched-AFR [Trj]
CynetMalicious (score: 100)
KasperskyWorm.Win32.VB.fer
BitDefenderGen:Trojan.Heur.zu0@sfmY@ihib
NANO-AntivirusTrojan.Win32.VB.epyowu
AegisLabWorm.Win32.VB.o!c
MicroWorld-eScanGen:Trojan.Heur.zu0@sfmY@ihib
TencentTrojan.Win32.Agent.bc
Ad-AwareGen:Trojan.Heur.zu0@sfmY@ihib
EmsisoftGen:Trojan.Heur.zu0@sfmY@ihib (B)
ComodoWorm.Win32.Agent.VBC@4×4502
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen7.15056
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroWORM_VOBFUS.NER
McAfee-GW-EditionBehavesLike.Win32.VBObfus.gz
SophosML/PE-A + Troj/Agent-APXD
Paloaltogeneric.ml
JiangminWorm/VB.pcc
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.VB.fer
KingsoftWin32.Heur.KVM007.a.(kcloud)
GridinsoftTrojan.Win32.Agent.bot!s1
MicrosoftWorm:Win32/Mofksys.R!MTB
ViRobotWorm.Win32.A.VB.402944
ZoneAlarmWorm.Win32.VB.fer
GDataGen:Trojan.Heur.zu0@sfmY@ihib
AhnLab-V3Worm/Win32.AutoRun.R49416
Acronissuspicious
BitDefenderThetaAI:Packer.6FA29F221D
ALYacGen:Trojan.Heur.zu0@sfmY@ihib
MAXmalware (ai score=82)
VBA32Worm.VB
MalwarebytesNimnul.Virus.FileInfector.DDS
ZonerTrojan.Win32.45187
ESET-NOD32Win32/VB.PEU
TrendMicro-HouseCallWORM_VOBFUS.NER
RisingWorm.Win32.VBCode.dp (CLOUD)
YandexTrojan.GenAsa!u5UU/PWv6tw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/VB.PEU!tr
AVGWin32:Patched-AFR [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureWorm.Vb.fer

How to remove Win32/VB.PEU?

Win32/VB.PEU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment