Malware

About “Win32:VB-AASR [Trj]” infection

Malware Removal

The Win32:VB-AASR [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-AASR [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-AASR [Trj]?


File Info:

name: 93CCF5217C17AB5C6E4C.mlw
path: /opt/CAPEv2/storage/binaries/aeaa7bc1f97b74048aad8a39fa0a4d419920e302e11c5abbfbf14a4a0c462adb
crc32: EBDD4240
md5: 93ccf5217c17ab5c6e4c8b199a76ecbd
sha1: 7dc1e548778c79a08cd0c425f3f8b1512f6be162
sha256: aeaa7bc1f97b74048aad8a39fa0a4d419920e302e11c5abbfbf14a4a0c462adb
sha512: 39e8404764e675837ab5f71a0ba3194d753f6dab6d38549daac07dc09b92d4e93f1c4c9d4811bc3c1d5c9088dd5a20e679948872ccb8ebb6b97c376b208e3de1
ssdeep: 6144:nL5ToHiUBiGyuT236J2deiEx4PvRo53Fv:9kjiaW6J2d/DPvkv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14444811972C0F77ED821C6F43A5643A4A53EED332491A807E6D21F1A37B5E87E261363
sha3_384: e5ce24581e24f30ee6c3dc2a080a640d06762e063619675fed3bca53843584759d46bd2909a937e5891ea339dc9761c7
ep_bytes: 6810404000e8f0ffffff000000000000
timestamp: 2012-01-14 07:23:56

Version Info:

0: [No Data]

Win32:VB-AASR [Trj] also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWorm.Siggen.8271
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.93ccf5217c17ab5c
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.VBInject.11
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.8778c7
BitDefenderThetaGen:NN.ZevbaF.36744.qmW@aanFvKci
VirITTrojan.Win32.Zyx.HH
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AQN
APEXMalicious
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.efid
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.Otran.jwdzws
SUPERAntiSpywareTrojan.Agent/Gen-Multi[VB]
AvastWin32:VB-AASR [Trj]
TencentWorm.Win32.Vobfus.kh
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureTrojan.TR/Otran.aymb
BaiduWin32.Trojan.VBObfus.f
TrendMicroWORM_VOBFUS.SM10
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-U
IkarusWorm.Win32.Vobfus
MAXmalware (ai score=83)
GDataGen:Variant.VBInject.11
GoogleDetected
AviraTR/Otran.aymb
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Diple.EMIB@4pez3w
ArcabitTrojan.VBInject.11
ViRobotTrojan.Win32.A.Vobfus.266240.A
ZoneAlarmWorm.Win32.Vobfus.efid
MicrosoftWorm:Win32/Vobfus.gen!R
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R19883
Acronissuspicious
VBA32BScope.Trojan-Dropper.Injector
ALYacGen:Variant.VBInject.11
TACHYONWorm/W32.Vobfus.266240
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM10
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!SaCOTwa1z30
SentinelOneStatic AI – Malicious PE
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AASR [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:VB-AASR [Trj]?

Win32:VB-AASR [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment