Malware

Win32:VB-ACOY [Trj] removal instruction

Malware Removal

The Win32:VB-ACOY [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ACOY [Trj] virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
ns1.musiczipz.com
ns1.musicmixa.net
ns1.musicmixa.org
ns1.musicmixb.co
ns1.musicmixc.com

How to determine Win32:VB-ACOY [Trj]?


File Info:

crc32: BD5719C7
md5: fe6e338fd58d7c2d867906cfa16388cf
name: FE6E338FD58D7C2D867906CFA16388CF.mlw
sha1: 1c88aa3f59d83295a3d253fd9bf809bdc5accd12
sha256: 4294933d0b0fd6b40e8635109a0d9e08be3b78db26f7099903160bb6bf9cbf4a
sha512: 1a3e69ddd8671ec9bfe8514e81e76b5df69c340eae2a6e1aab93f54a80615c8a36a9e89865cc4ef01ea9ba2a6e18fb8636aa2eaf3ab390b0476993a993bee3bb
ssdeep: 1536:DjB3hsXVyxO3fs8koyFFx57Yj3oJoFDuhQHy4ktju:nJCl6AfMLEj3oJoAhayju
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 7.08.0002
InternalName: xbadmknh
FileVersion: 7.08.0002
OriginalFilename: xbadmknh.exe
ProductName: drglbntuj

Win32:VB-ACOY [Trj] also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.2424
FireEyeGeneric.mg.fe6e338fd58d7c2d
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.2424
CylanceUnsafe
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Barys.2424
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.VB.au
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup
APEXMalicious
AvastWin32:VB-ACOY [Trj]
ClamAVWin.Trojan.VBTrojan3-6118226-0
KasperskyTrojan.Win32.VBKrypt.ltuh
NANO-AntivirusTrojan.Win32.VBKrypt.covjxo
TencentWorm.Win32.Vobfus.n
Ad-AwareGen:Variant.Barys.2424
EmsisoftGen:Variant.Barys.2424 (B)
ComodoTrojWare.Win32.VB.AVA@4paxk7
F-SecureTrojan.TR/Barys.2229.jh.4
DrWebTrojan.DownLoader11.20151
VIPRETrojan.Win32.Vobfus.a (v)
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
SophosML/PE-A + Mal/VBCheMan-J
IkarusTrojan.Win32.Vobfus
JiangminTrojan/Vobfus.gaz
AviraTR/Barys.2229.jh.4
eGambitUnsafe.AI_Score_100%
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!U
ArcabitTrojan.Barys.D978
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmTrojan.Win32.VBKrypt.ltuh
GDataGen:Variant.Barys.2424
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R24169
Acronissuspicious
McAfeeVBObfus.dv
TACHYONTrojan/W32.VBKrypt.118784
VBA32SScope.Malware-Cryptor.VBCR.3042
MalwarebytesVobfus.Worm.Evasion.DDS
PandaW32/Vobfus.GEW.worm
ESET-NOD32a variant of Win32/AutoRun.VB.AVG
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.Win32.VBCode.ef (CLASSIC)
YandexTrojan.GenAsa!DXurx68NXHc
SentinelOneStatic AI – Malicious PE – Worm
MaxSecureTrojan.VBKrypt.ltuh
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.34804.hm0@aOas8npi
AVGWin32:VB-ACOY [Trj]
Cybereasonmalicious.fd58d7
Qihoo-360HEUR/QVM03.0.057B.Malware.Gen

How to remove Win32:VB-ACOY [Trj]?

Win32:VB-ACOY [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment