Malware

Win32:VB-ABOX [Trj] (file analysis)

Malware Removal

The Win32:VB-ABOX [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ABOX [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-ABOX [Trj]?


File Info:

name: 02E36E18D008E97D00FA.mlw
path: /opt/CAPEv2/storage/binaries/ae3ae43b561b0daf99fa0e5ae59dbc8982485684272dca85cc4dd453eaaaef3a
crc32: A31B04DA
md5: 02e36e18d008e97d00fac8f0ba704078
sha1: 5467cee560001f82ed447eafe4dd1b4cbcf9d3c0
sha256: ae3ae43b561b0daf99fa0e5ae59dbc8982485684272dca85cc4dd453eaaaef3a
sha512: 9d97541ab905a5fcddb3d7f2c9be06e42f78b5afb4bccc024be94f5683fe7bb4e3298ab4cdb42a150af2b431a2dc7ae0e58fdd4aef54d032cadb52223bdb6ed9
ssdeep: 3072:045JukiibdBG5XoC8ctR8imbQhpwI9J5zTbK2VzvPpi52mwzlM9I9IjtQ/Ba:PhtnhctRnmMhpL9J53vTRi52mwzBkQ/8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13464D6397390F73EE521C6F92D9983A4046DAD3611E1E40BF7C12B1A36F1AD792207A7
sha3_384: 0d2616ada65bf2550d1038f5aedb5f2ab8e5b7e0ec6b05e14b0aba1dd2246e638c9c202ccf18a92334f867f694511d8a
ep_bytes: 68084c4000e8eeffffff000000000000
timestamp: 2012-03-07 19:35:56

Version Info:

0: [No Data]

Win32:VB-ABOX [Trj] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.460977
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.ft
McAfeeVBObfus.dr
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.460977
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.560001
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.Zyx.PA
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ASV
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dabf
BitDefenderGen:Variant.Zusy.460977
NANO-AntivirusTrojan.Win32.Inject.covlqa
AvastWin32:VB-ABOX [Trj]
TencentWorm.Win32.Vobfus.hu
EmsisoftGen:Variant.Zusy.460977 (B)
F-SecureTrojan.TR/Kazy.62009.2
DrWebTrojan.VbCrypt.150
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.02e36e18d008e97d
SophosMal/SillyFDC-V
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
GDataGen:Variant.Zusy.460977
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Kazy.62009.2
VaristW32/Vobfus.AV.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Zusy.D708B1
ViRobotTrojan.Win32.A.VB.237568.G
ZoneAlarmWorm.Win32.Vobfus.dabf
MicrosoftWorm:Win32/Vobfus!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Jorik.R573629
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36744.tmZ@aGlOqup
ALYacGen:Variant.Zusy.460977
VBA32BScope.Trojan.Ymacco
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.Autorun!1.99E9 (CLASSIC)
YandexTrojan.GenAsa!Br32YRZH23s
IkarusSality.Win32
MaxSecureTrojan.Malware.11745024.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABOX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:VB-ABOX [Trj]?

Win32:VB-ABOX [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment