Malware

Win32:VB-AAET [Trj] removal instruction

Malware Removal

The Win32:VB-AAET [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-AAET [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-AAET [Trj]?


File Info:

name: FC237AF5E558D0CF43D8.mlw
path: /opt/CAPEv2/storage/binaries/b7ab11a8c41ecf9f86f82d237d9e791a4fc96b2932979cf3b815e35a9e2ed04d
crc32: 7CDA9A24
md5: fc237af5e558d0cf43d8eb4a40a43e3a
sha1: 9405e754c2a5b9a31d5e30821d80fe55031588d8
sha256: b7ab11a8c41ecf9f86f82d237d9e791a4fc96b2932979cf3b815e35a9e2ed04d
sha512: 2d21a42519e731750455352801f7bb59b201c76895ffd54b16c7be078438a2c93ae7957917f027d329941fbca97fc31362f1b148b4a56e7a477c7af625fb649a
ssdeep: 3072:eW4MlXL7KvWeRl6Knvmb7/D26DKcAA6vQOm34lK5/si+iS36:/XCVREKnvmb7/D26DKcV67m34E5/s8SK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D404D812BB09B06BE183D4F05E28C69A392D6D7623D0BC4777857F296A70597B8B031F
sha3_384: 1c1bab6b16143b53e67d5a5952a0c31595cca1d4cc44977d0746c2021bd2517b0d97c4368b2e048b488f8bf6a367bfd6
ep_bytes: 6828384000e8eeffffff000000000000
timestamp: 2011-12-05 18:17:21

Version Info:

0: [No Data]

Win32:VB-AAET [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Sirefef.942
FireEyeGeneric.mg.fc237af5e558d0cf
CAT-QuickHealTrojan.JorikVMF.S19741166
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.cd
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.Vobfus.KDN
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AQE
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.efhi
BitDefenderGen:Variant.Sirefef.942
NANO-AntivirusTrojan.Win32.Jorik.cqkyjh
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
AvastWin32:VB-AAET [Trj]
TencentWorm.Win32.Vobfus.kq
TACHYONTrojan/W32.VB-Jorik.188416.I
SophosMal/SillyFDC-T
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SMAB
EmsisoftGen:Variant.Sirefef.942 (B)
IkarusWorm.Win32.Vobfus
GoogleDetected
AviraTR/Dropper.Gen7
VaristW32/Vobfus.AA.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Sirefef.942
ViRobotTrojan.Win32.Jorik.188416.B
ZoneAlarmWorm.Win32.Vobfus.efhi
GDataGen:Variant.Sirefef.942
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R16967
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.lmW@a4c1eEhi
ALYacGen:Variant.Sirefef.942
MAXmalware (ai score=81)
VBA32BScope.Trojan.Jorik
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.AutoRun!1.E3C6 (CLASSIC)
YandexTrojan.GenAsa!x1tuGxxa0wU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AAET [Trj]
Cybereasonmalicious.5e558d
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.98fd7202

How to remove Win32:VB-AAET [Trj]?

Win32:VB-AAET [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment