Malware

Win32:VB-ABQA [Trj] information

Malware Removal

The Win32:VB-ABQA [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ABQA [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-ABQA [Trj]?


File Info:

name: B199AEAB861A939870FF.mlw
path: /opt/CAPEv2/storage/binaries/2e6620d87dceea08dfcf5246964bf7ba659a1032faad3e22b2d4194a6b4f4244
crc32: 054B494A
md5: b199aeab861a939870ff4d65e5e2b8f1
sha1: c6dfb85a0d2c13ac6b3740cf8290791ad627c89a
sha256: 2e6620d87dceea08dfcf5246964bf7ba659a1032faad3e22b2d4194a6b4f4244
sha512: 59b528153bb5d9a86a1229c5364a29e411ca9267370bec937ddf9d96139d9d9649d7cd350448cc3df48c2fb16258d7b62914d9bb377bfa0b5eabdac3a55257ec
ssdeep: 3072:NVeVC5NpUU+mzihKh8wpzDqulR3X9sDpLg6ZGKIXeYnVlDY:NVejEV82llbs1g6+XbVS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18514F7397281E73EE521C6F92CA683A4406D6D3615E1E41BFBC2271935F1AE7D3207A3
sha3_384: 3f5dd223aaf18a4ae50ad835426a169a6c409589e4712db874829d44565bcf2196846407080db35e83718fa7f19515b7
ep_bytes: 6868434000e8f0ffffff000000000000
timestamp: 2012-03-10 21:30:09

Version Info:

0: [No Data]

Win32:VB-ABQA [Trj] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.mdoW
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.95834
FireEyeGeneric.mg.b199aeab861a9398
CAT-QuickHealTrojan.Beebone.D
ALYacTrojan.GenericKDZ.95834
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPRETrojan.GenericKDZ.95834
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderTrojan.GenericKDZ.95834
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Inject.n
VirITWorm.Win32.Generic.BJWU
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ATA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.gtpu
AlibabaWorm:Win32/Jorik.fc47a06e
NANO-AntivirusTrojan.Win32.WBNA.jvynem
ViRobotWorm.Win32.A.WBNA.278528.HE
RisingWorm.VobfusEx!1.99DB (CLASSIC)
EmsisoftTrojan.GenericKDZ.95834 (B)
F-SecureWorm.WORM/Vobfus.S.200
DrWebWorm.Siggen.6649
ZillyaTrojan.Jorik.Win32.1002665
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-V
IkarusTrojan.Win32.Vobfus
JiangminTrojan/Vbobf.b
AviraWORM/Vobfus.S.200
MAXmalware (ai score=81)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!R
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1765A
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmTrojan.Win32.Jorik.Vobfus.gtpu
GDataTrojan.GenericKDZ.95834
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R64119
McAfeeGeneric VB.kk
TACHYONTrojan/W32.Agent.208896.B
DeepInstinctMALICIOUS
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!hW3s5gOKwOE
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Injector.dgif
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36196.mmW@aO2rj0hi
AVGWin32:VB-ABQA [Trj]
Cybereasonmalicious.b861a9
AvastWin32:VB-ABQA [Trj]

How to remove Win32:VB-ABQA [Trj]?

Win32:VB-ABQA [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment