Malware

Win32/VB.SBD malicious file

Malware Removal

The Win32/VB.SBD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.SBD virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Korean
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ekyenc.co.kr

How to determine Win32/VB.SBD?


File Info:

crc32: E34C6123
md5: 03c04b834563f370795eb001e2cbf9a1
name: 03C04B834563F370795EB001E2CBF9A1.mlw
sha1: 8bf4505ff150061f9fce47d8b5ebc5bc1309dcbb
sha256: f8ecb6dd0a7d3099938c648c248326eb0350d62aa477d43913cc038c903d0be6
sha512: 5c7c843f861db329af28f3212693363603be405d1b1e629d57c440354c92a5e813f200a08a812599678244058f943e9f8177ecdc9463e12eda65f146b1002afa
ssdeep: 384:83GY8YiZY99FeYWKif6RdyiEsdZ42vMZgc7Tg+E6k3:83LPiZY99FeYWbody32vMZgc7Tg56k3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0412 0x04b0
LegalCopyright: KGRID CO.,Ltd
InternalName: svrepeter
FileVersion: 1.00.0003
CompanyName: KGRID CO.,Ltd
ProductName: svrpeter
ProductVersion: 1.00.0003
OriginalFilename: svrepeter.exe

Win32/VB.SBD also known as:

BkavW32.AIDetectVM.malware1
FireEyeGeneric.mg.03c04b834563f370
Qihoo-360HEUR/QVM03.0.Malware.Gen
McAfeeArtemis!03C04B834563
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Seco-9757470-0
KasperskyTrojan.Win32.Seco.kn
NANO-AntivirusTrojan.Win32.Seco.dtpewc
AegisLabTrojan.Win32.Seco.4!c
AvastWin32:Malware-gen
ComodoMalware@#2ofoeave6igkl
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader14.21088
ZillyaBackdoor.CPEX.Win32.31567
TrendMicroTROJ_SECO.D
McAfee-GW-EditionBehavesLike.Win32.Trojan.nt
JiangminTrojan.Seco.a
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Seco
KingsoftWin32.Troj.Seco.kn.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!bit
ZoneAlarmTrojan.Win32.Seco.kn
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZevbaF.34804.cm0@aW3veypG
VBA32Trojan.Seco
MalwarebytesGeneric.Malware/Suspicious
ESET-NOD32a variant of Win32/VB.SBD
TrendMicro-HouseCallTROJ_SECO.D
TencentWin32.Trojan.Seco.Frs
YandexTrojan.GenAsa!eIo9keuPwYo
IkarusTrojan.Win32.Seco
FortinetW32/Seco.KN!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Win32/VB.SBD?

Win32/VB.SBD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment