Malware

How to remove “Win32/Vybab.A”?

Malware Removal

The Win32/Vybab.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Vybab.A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed

How to determine Win32/Vybab.A?


File Info:

name: A4F6DAAE3F19CED15152.mlw
path: /opt/CAPEv2/storage/binaries/112c3b6fb1eb64ade9992e945e2152ca855178d0ab79de0fd531c925e8ad750b
crc32: DAA3CDE3
md5: a4f6daae3f19ced15152ec468aba4b41
sha1: 63d9e45a4279f77b08f2bfc683b9d4e45525730d
sha256: 112c3b6fb1eb64ade9992e945e2152ca855178d0ab79de0fd531c925e8ad750b
sha512: e0f8c2b233504f908e89c3463f880dc47117cec2b037b5b6d5f2a8ac8755892ca025f90d789a68b1a9bfa3ebc1c296ebe33212b4655b78e3520c343618372770
ssdeep: 12288:dNYMrRgg5HTq/zofXyc+MZd0qG5v9KbyEFeaj4P9/s6u6:dNYGlM/KCtMZd0qgKWEfes6X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BF47C17F19240FAD41AC479CB5AA231E83678AE1B7434EF16D4DB441E37BE06738B86
sha3_384: 1379c902ad9a9d6a044e491b9060ed93e8130f4c35d9b7cb191a1cc7bba796f3ef511a35044797ca7c98f97d21590a40
ep_bytes: 558bec83c4f0535657b8fcdd4100e86d
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Vybab.A also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.ScriptWorm.EBD63950
FireEyeGeneric.mg.a4f6daae3f19ced1
CAT-QuickHealW32.Vybab.A8
SkyhighBehavesLike.Win32.Vybab.bh
McAfeeW32/Vybab@MM
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005036331 )
AlibabaWorm:Win32/Vybab.110ed
K7GWTrojan ( 005036331 )
BitDefenderThetaGen:NN.ZelphiF.36804.WGZ@aexu!1ib
SymantecW32.Vybab@mm
ESET-NOD32Win32/Vybab.A
APEXMalicious
TrendMicro-HouseCallPE_VYBAB.A
Paloaltogeneric.ml
ClamAVWin.Worm.Vybab-9924722-0
KasperskyEmail-Worm.Win32.Vybab
BitDefenderDropped:Generic.ScriptWorm.EBD63950
NANO-AntivirusTrojan.Win32.Vybab.eoig
AvastWin32:Vybab [Wrm]
TencentEmail-Worm.Win32.Vybab.xa
EmsisoftDropped:Generic.ScriptWorm.EBD63950 (B)
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLM.Vybab
VIPREDropped:Generic.ScriptWorm.EBD63950
TrendMicroPE_VYBAB.A
Trapminemalicious.moderate.ml.score
SophosMal/Generic-R
MAXmalware (ai score=85)
JiangminI-Worm/Babyv
GoogleDetected
AviraDR/Delphi.Gen
VaristW32/Vybab.OVIY-6481
Antiy-AVLTrojan/Win32.Vybab.a
KingsoftWin32.Troj.Undef.a
MicrosoftWorm:Win32/Vybab.A@mm
XcitiumWorm.Win32.Vybab.A@30gu
ArcabitGeneric.ScriptWorm.EBDDF9CE
ZoneAlarmEmail-Worm.Win32.Vybab
GDataDropped:Generic.ScriptWorm.EBD63950
CynetMalicious (score: 100)
AhnLab-V3Win32/Vybab.141824
VBA32TScope.Trojan.Delf
ALYacDropped:Generic.ScriptWorm.EBD63950
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingWorm.BabyV (CLASSIC)
YandexTrojan.GenAsa!Co1yPIrQULQ
IkarusWorm.Win32.Vybab
MaxSecureTrojan.Malware.1842041.susgen
FortinetW32/Vybab.A@mm
AVGWin32:Vybab [Wrm]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/Vybab.A?

Win32/Vybab.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment