Malware

How to remove “Win32:VB-ABSZ [Trj]”?

Malware Removal

The Win32:VB-ABSZ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ABSZ [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-ABSZ [Trj]?


File Info:

name: 6E836C7D1708A17C19DE.mlw
path: /opt/CAPEv2/storage/binaries/c2af1cda34654aa06a0e778f0b10941eac7daabe8c7e764fe9f0d6fda9004f9e
crc32: 0F3F4FCE
md5: 6e836c7d1708a17c19de7e3be537e448
sha1: 1704b497cf4c62c8ff00248ea99a27ab78fcc3e9
sha256: c2af1cda34654aa06a0e778f0b10941eac7daabe8c7e764fe9f0d6fda9004f9e
sha512: feb5110e7f0ceb813035bebc7cd6f5b2769161abb926318e36ba75e5caec57314872396b312510db004714620c908331f1e26ef572b491e4353877c05200393f
ssdeep: 3072:FI5nBS9YUdtG716ennADVeMfcRAGKB+uMTEd1CTG:Fi+u1tnADVhERAGKB+uSEdl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1240482397240E33DE425C7F82CAA83A4546DAD3616D1A81BF7C26B1971F1AB3D630397
sha3_384: e77c3a6c127b3936c926f0a819b07595f680b19fccb7e37ba1a49f7c5faacc7273f7ed87af933e71d65f9f58890f2d52
ep_bytes: 68503d4000e8eeffffff000000000000
timestamp: 2012-03-16 19:40:18

Version Info:

FileVersion: 2.90
ProductVersion: 2.90
Translation: 0x0409 0x04b0

Win32:VB-ABSZ [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
CAT-QuickHealWorm.VobfusVMF.S19740159
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.dv
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.VBInject.11
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.Generic.BMWH
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ATJ
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMK5
ClamAVWin.Trojan.VB-73745
KasperskyWorm.Win32.Vobfus.davp
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.WBNA.cqkyfu
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABSZ [Trj]
RisingWorm.VobfusEx!1.99DC (CLASSIC)
EmsisoftGen:Variant.VBInject.11 (B)
GoogleDetected
F-SecureWorm.WORM/Vobfus.R.20
DrWebWorm.Siggen.6520
TrendMicroWORM_VOBFUS.SMK5
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.6e836c7d1708a17c
SophosMal/SillyFDC-W
SentinelOneStatic AI – Malicious PE
JiangminWorm.Vobfus.jdlx
WebrootW32.Worm.Gen
VaristW32/Vobfus.BE.gen!Eldorado
AviraWORM/Vobfus.R.20
MAXmalware (ai score=88)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBInject.11
ViRobotWorm.Win32.A.WBNA.188416.EJ
ZoneAlarmWorm.Win32.Vobfus.davp
GDataGen:Variant.VBInject.11
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R22840
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.lm1@ay7!vDii
ALYacGen:Variant.VBInject.11
VBA32BScope.Trojan.Ymacco
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TencentTrojan.Win32.FakeFolder.cce
YandexTrojan.GenAsa!2dqV7Qvi5ys
IkarusWorm.Win32.Vobfus
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABSZ [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.44efed89

How to remove Win32:VB-ABSZ [Trj]?

Win32:VB-ABSZ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment