Malware

How to remove “Win32:VB-ACNQ [Trj]”?

Malware Removal

The Win32:VB-ACNQ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ACNQ [Trj] virus can do?

  • Executable code extraction
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.spansearcher.net

How to determine Win32:VB-ACNQ [Trj]?


File Info:

crc32: 2E7184B3
md5: b55c9238ddd1a8abd154093749b656cd
name: B55C9238DDD1A8ABD154093749B656CD.mlw
sha1: 86fb0fe4d44ec568bfe84e61f570e558523d29d8
sha256: cccba28a5d6be99ad43b5c2e06e573249aa49bf1ea112cf3e14ee3ec5c610b59
sha512: ea39422e0fd232aa902c383440dcc5f46f7b8808cb36ffa34b66d77d70230f81167beed0c4a987ad633a307ef2cd7952484cc88f2378272abc2a8178fac2377b
ssdeep: 3072:bCETo/0YxOOW0tQ9nLHbB9WPliBs2HWWEakGJm9BA:bCJYL4QxL7B9WPli+yWWEazi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 7.08.0002
InternalName: zkmuavocri
FileVersion: 7.08.0002
OriginalFilename: zkmuavocri.exe
ProductName: tdnzzumh

Win32:VB-ACNQ [Trj] also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.6261
FireEyeGeneric.mg.b55c9238ddd1a8ab
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Symmi.6261
CylanceUnsafe
VIPRETrojan.Win32.Vobfus.a (v)
AegisLabWorm.Win32.WBNA.kZq0
SangforMalware
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Symmi.6261
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.8ddd1a
BitDefenderThetaGen:NN.ZevbaF.34804.oq0@aafaimpi
CyrenW32/Vobfus.J.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/Pronny.AI
BaiduWin32.Worm.Pronny.h
APEXMalicious
AvastWin32:VB-ACNQ [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.VBNA.bdmh
AlibabaWorm:Win32/VBInject.12f38fa0
NANO-AntivirusTrojan.Win32.VB.cqkxpf
ViRobotTrojan.Win32.VB.204800.H
Ad-AwareGen:Variant.Symmi.6261
SophosML/PE-A + Mal/VBCheMan-G
ComodoWorm.Win32.Pronny.AK@4ogvoo
F-SecureTrojan.TR/VB.Inject.11591
DrWebWin32.HLLW.Autoruner1.15026
TrendMicroWORM_VOBFUS.SME
McAfee-GW-EditionBehavesLike.Win32.Downloader.dm
EmsisoftGen:Variant.Symmi.6261 (B)
IkarusTrojan.Patched
JiangminWorm/VBNA.gybw
AviraTR/VB.Inject.11591
MAXmalware (ai score=81)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftVirTool:Win32/VBInject.WX
ArcabitTrojan.Symmi.D1875
SUPERAntiSpywareTrojan.Agent/Gen-Autorun[VB]
AhnLab-V3Trojan/Win32.VB.R40142
ZoneAlarmWorm.Win32.VBNA.bdmh
GDataGen:Variant.Symmi.6261
CynetMalicious (score: 100)
TotalDefenseWin32/Vobfus.AFO
Acronissuspicious
McAfeeVBObfus.dv
TACHYONTrojan/W32.VB-Agent.237568.CB
VBA32SScope.Malware-Cryptor.VBCR.3042
MalwarebytesVobfus.Worm.Evasion.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SME
RisingWorm.VobfusEx!1.99DC (CLOUD)
YandexTrojan.GenAsa!KnbUZ/Nfsmk
SentinelOneStatic AI – Malicious PE – Worm
MaxSecureWorm.W32.VBNA.bdmh
FortinetW32/Jorik.EGLG!tr
AVGWin32:VB-ACNQ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Worm.Win32.VB.T

How to remove Win32:VB-ACNQ [Trj]?

Win32:VB-ACNQ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment