Malware

Win32:VB-ABRX [Trj] malicious file

Malware Removal

The Win32:VB-ABRX [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ABRX [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-ABRX [Trj]?


File Info:

name: 0E9A3C6318B5138B0091.mlw
path: /opt/CAPEv2/storage/binaries/160c3a9b1dec77a77c1017ae2893596065078f3b89945f98eaf43f586231e4e3
crc32: 151B3313
md5: 0e9a3c6318b5138b0091cdce1f6c462b
sha1: 925353df35add4ca8b2f01e95dad3476f2dd1d16
sha256: 160c3a9b1dec77a77c1017ae2893596065078f3b89945f98eaf43f586231e4e3
sha512: a7ac575786bfe49c60a0b36e721468bed7a36174aa74865cf611a62ca403fe28dd3f234be53779e760cfeef0dc9a80e8e2caef79f9bd1289959c66d8c806a9ca
ssdeep: 3072:hJsjHucQPGDQicxBrGB+GJuyG5/YL1oxR8hXQ:hJsRQP4aGjQyF1yYg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10414A47A7390A73ED425C7F83CAE83A4502DAD3511C5A417F7C12B1A72E2AF79220767
sha3_384: 012e5022aa49ebb58d9245d40aa9327bdf50fa415e77332c1f9006b635316e9160f0eb4396be04837302c60c8ca62351
ep_bytes: 6850434000e8f0ffffff000000000000
timestamp: 2012-03-14 07:56:00

Version Info:

FileVersion: 3.00
ProductVersion: 3.00
Translation: 0x0409 0x04b0

Win32:VB-ABRX [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.0e9a3c6318b5138b
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGeneric VB.kk
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.SHeur4.UJB
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ATG
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.efwi
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.Vobfus.fnzzvd
AvastWin32:VB-ABRX [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.Vobfus.200704.C
EmsisoftGen:Variant.VBInject.11 (B)
GoogleDetected
F-SecureWorm.WORM/VBNA.bztzre
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.VBInject.11
TrendMicroWORM_VOBFUS.SMD1
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-AC
IkarusWorm.Win32.Vobfus
JiangminTrojan/Vbobf.b
VaristW32/Vobfus.AD.gen!Eldorado
AviraWORM/VBNA.bztzre
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.gen!R
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.VBInject.11
ViRobotWorm.Win32.A.WBNA.200704.BQ
ZoneAlarmWorm.Win32.Vobfus.efwi
GDataGen:Variant.VBInject.11
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R22840
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.mm0@a4jBuZfi
ALYacGen:Variant.VBInject.11
MAXmalware (ai score=89)
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMD1
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
YandexTrojan.GenAsa!hW3s5gOKwOE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABRX [Trj]
Cybereasonmalicious.318b51
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.0dbfaad8

How to remove Win32:VB-ABRX [Trj]?

Win32:VB-ABRX [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment