Malware

Win32:VB-AAFE [Trj] removal guide

Malware Removal

The Win32:VB-AAFE [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-AAFE [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-AAFE [Trj]?


File Info:

name: C1BD9320FF463F00F48F.mlw
path: /opt/CAPEv2/storage/binaries/f6e3d6391dd0a48234e786a1462714997464a92a26d3e2fbc7dc8417ba32a34e
crc32: 93526D2F
md5: c1bd9320ff463f00f48f5fcb6862ab7b
sha1: cbef9b1b170d946506ac35ab8eeffe615aff6315
sha256: f6e3d6391dd0a48234e786a1462714997464a92a26d3e2fbc7dc8417ba32a34e
sha512: 5ab8e81197cd7ee2f21b42f9e184521910bdc127ad63fb94e28a64aa9285f08483e2599e7084dd9056cf4e405a6195c9c9e8b110ebc7866ad6d7c7aeaecdda0c
ssdeep: 6144:rZs7Knvmb7/D26rfo9Am26fBXMZ8R3FXjrCTYTQdq4qJUGQBSpYCbwN:rZs7Knvmb7/D26zZ8R3FXjrC8T8q4qJM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB14DA16A758B4BBD543D5F06D2C979634292E7913D0FC473280BF14A6B06ABB9B032F
sha3_384: 3723b858adc5008efd0b51967e55f947a8cb5cb60d83a3ddfec9d5a5f267357b558e3c3a73114e7ccc27264065248ae6
ep_bytes: 68743b4000e8f0ffffff000000000000
timestamp: 2011-12-07 20:30:06

Version Info:

0: [No Data]

Win32:VB-AAFE [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lsgT
DrWebTrojan.VbCrypt.150
MicroWorld-eScanTrojan.GenericKDZ.95821
FireEyeGeneric.mg.c1bd9320ff463f00
CAT-QuickHealWorm.VobfusVMF.S19740081
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.ch
Cylanceunsafe
VIPRETrojan.GenericKDZ.95821
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.633aaa83
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.0ff463
BitDefenderThetaGen:NN.ZevbaF.36802.mmX@a8FeAZi
VirITWorm.Win32.Generic.BDZR
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AQE
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Otran-81
KasperskyWorm.Win32.Vobfus.efkq
BitDefenderTrojan.GenericKDZ.95821
NANO-AntivirusTrojan.Win32.WBNA.cqkxxa
AvastWin32:VB-AAFE [Trj]
TencentWorm.Win32.Vobfus.bu
TACHYONTrojan/W32.VB-Jorik.208896.I
EmsisoftTrojan.GenericKDZ.95821 (B)
GoogleDetected
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.Autorun.l
TrendMicroWORM_VOBFUS.SMAB
Trapminesuspicious.low.ml.score
SophosMal/SillyFDC-T
IkarusSality.Win32
JiangminWorm.Vobfus.ksjr
VaristW32/VBInject.BG.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D1764D
ViRobotTrojan.Win32.A.Diple.204800.D
ZoneAlarmWorm.Win32.Vobfus.efkq
GDataTrojan.GenericKDZ.95821
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R123674
Acronissuspicious
VBA32BScope.Trojan-Dropper.VB.01545
ALYacTrojan.GenericKDZ.95821
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.AutoRun!1.E3C6 (CLASSIC)
YandexTrojan.GenAsa!OoaBkc/rPp0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Diple.dmqa
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AAFE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan.Win.UnkAgent

How to remove Win32:VB-AAFE [Trj]?

Win32:VB-AAFE [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment