Malware

Win32:VB-ABOX [Trj] removal guide

Malware Removal

The Win32:VB-ABOX [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ABOX [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-ABOX [Trj]?


File Info:

name: 33466BAB565492D5EDB4.mlw
path: /opt/CAPEv2/storage/binaries/36bbee9dc8cec2a6af0bcebfbcebacde9bf93587663d7511bbb5be90dd2a0a5e
crc32: EB65CCB5
md5: 33466bab565492d5edb4f88408b03c1f
sha1: 3d03a5ffbe015854759e0015b0d7dcd3e3b0395a
sha256: 36bbee9dc8cec2a6af0bcebfbcebacde9bf93587663d7511bbb5be90dd2a0a5e
sha512: 8f5f1d8053e7c99210a17cf1875120d585131044bbb0f4da1b51524299d0b5d5b45a3021b50361d1266b99292ea202cfc545f4f76b80877368873a2fc8bc093e
ssdeep: 3072:04TJQ50ibdBG5XoC8ctR8imbQhpwI9J5zTbK2VzvPpi52mwzlM9I9IjtQ/PS:PsnhctRnmMhpL9J53vTRi52mwzBkQ/6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB64D6397790F73EE521C6F92D9983A4046DAC3611E1E40BF7C12B1A36F1AD792207A7
sha3_384: a7495c023a4b4598044f5f3330a22eed7ac2c30f05b1430956358f8d7e20ae00745a5ea9f9b4d2f84866813dc5eebd26
ep_bytes: 68084c4000e8eeffffff000000000000
timestamp: 2012-03-07 19:35:56

Version Info:

0: [No Data]

Win32:VB-ABOX [Trj] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.460977
FireEyeGeneric.mg.33466bab565492d5
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.ft
McAfeeVBObfus.dr
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.460977
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.Zyx.PA
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ASV
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dabf
BitDefenderGen:Variant.Zusy.460977
NANO-AntivirusTrojan.Win32.Inject.covlqa
AvastWin32:VB-ABOX [Trj]
TencentWorm.Win32.Vobfus.hu
EmsisoftGen:Variant.Zusy.460977 (B)
F-SecureTrojan.TR/Kazy.62009.2
DrWebTrojan.VbCrypt.150
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-V
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Kazy.62009.2
VaristW32/Vobfus.AV.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Zusy.D708B1
ViRobotTrojan.Win32.A.VB.237568.G
ZoneAlarmWorm.Win32.Vobfus.dabf
GDataGen:Variant.Zusy.460977
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Jorik.R573629
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.tmZ@aGlOqup
ALYacGen:Variant.Zusy.460977
VBA32BScope.Trojan.Ymacco
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.Autorun!1.99E9 (CLASSIC)
YandexTrojan.GenAsa!Br32YRZH23s
IkarusSality.Win32
MaxSecureTrojan.Malware.11745024.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABOX [Trj]
DeepInstinctMALICIOUS

How to remove Win32:VB-ABOX [Trj]?

Win32:VB-ABOX [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment