Malware

Win32:VB-ACFO [Trj] removal

Malware Removal

The Win32:VB-ACFO [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ACFO [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:VB-ACFO [Trj]?


File Info:

name: 624DEBDEF8AA383076DE.mlw
path: /opt/CAPEv2/storage/binaries/b232e3adaa74289765278bf8648e953a15d1e41e0864ffc6f57177dc886315f4
crc32: 0EDB8B10
md5: 624debdef8aa383076de5ac62c376a72
sha1: 495e39b6b7f6a90aa036a28192724235386a9696
sha256: b232e3adaa74289765278bf8648e953a15d1e41e0864ffc6f57177dc886315f4
sha512: a03c579d2c5592ecc7fc48193dd181dc957edf52ec6d016b946c59ed5d19fc5b966e898303aa09d805b74bb0761ff28a5d56b7dadf50d6a0237a942e67033f4f
ssdeep: 1536:hft0O82NTdwfzLGZcYADZPU1+73BD88b0nysNIjnZq:PwfugZPUQJsCnY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBA39023770414A8E978663467B786E739F3A89C4A0B65837B3436395C7FE421D21BE3
sha3_384: 58a9298aedd817682e3ba2b94c2beac8d251d09f963de85d3fd4c55db2440afa5495c5766950a0d04143d86eef3a98b9
ep_bytes: 6820124000e8eeffffff000000000000
timestamp: 2012-04-06 18:24:31

Version Info:

ProductName:
FileVersion: 1.88
ProductVersion: 1.77
InternalName:
OriginalFilename:
Translation: 0x0409 0x04b0

Win32:VB-ACFO [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lvqp
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.83003
ClamAVWin.Trojan.VB-1576
FireEyeGeneric.mg.624debdef8aa3830
CAT-QuickHealTrojan.Beebone.D
McAfeeW32/Autorun.worm.aaeh
Cylanceunsafe
VIPRETrojan.GenericKDZ.83003
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/SuperThreat.fb40
K7GWP2PWorm ( 0038227d1 )
K7AntiVirusEmailWorm ( 003c363a1 )
BaiduWin32.Trojan.SuperThreat.e
VirITTrojan.Win32.Zyx.KR
CyrenW32/VBInject.CO.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AUK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.SuperThreat.m
BitDefenderTrojan.GenericKDZ.83003
NANO-AntivirusTrojan.Win32.Jorik.cihuhi
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACFO [Trj]
TencentWorm.Win32.Vobfus.h
TACHYONTrojan/W32.SuperThreat.102400
EmsisoftTrojan.GenericKDZ.83003 (B)
F-SecureWorm.WORM/Vobfus.EG.90
DrWebWin32.HLLW.Autoruner1.14731
ZillyaTrojan.SuperThreatGen.Win32.1
TrendMicroWORM_VOBFUS.SMCK
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosW32/Vobfus-Z
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.83003
JiangminTrojan/SuperThreat.cuf
AviraWORM/Vobfus.EG.90
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1443B
ZoneAlarmTrojan.Win32.SuperThreat.m
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R23055
BitDefenderThetaGen:NN.ZevbaF.36318.gm0@aWW7Z2oi
ALYacTrojan.GenericKDZ.83003
MAXmalware (ai score=84)
VBA32Trojan.SuperThreat
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
ZonerTrojan.Win32.146867
TrendMicro-HouseCallWORM_VOBFUS.SMCK
RisingWorm.Vobfus!1.99C3 (CLASSIC)
YandexTrojan.GenAsa!NJz+QeX5uVg
IkarusTrojan.Win32.Vobfus
MaxSecureTrojan.W32.SuperThreat.m
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACFO [Trj]
DeepInstinctMALICIOUS

How to remove Win32:VB-ACFO [Trj]?

Win32:VB-ACFO [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment