Malware

Win32:VB-ADBH [Trj] removal guide

Malware Removal

The Win32:VB-ADBH [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADBH [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:VB-ADBH [Trj]?


File Info:

name: 7B11B8841D4672635A15.mlw
path: /opt/CAPEv2/storage/binaries/5dd1b9d8e39e5e357f81e67b89e4e0ffdb7053bf489bda61bd9f1657dc9cd2cf
crc32: D9F587E9
md5: 7b11b8841d4672635a15e036ec34ca43
sha1: e7a56bc73a939eeae3f01492bbf47938f6e8d827
sha256: 5dd1b9d8e39e5e357f81e67b89e4e0ffdb7053bf489bda61bd9f1657dc9cd2cf
sha512: 256923388d90cb2b18204869ce15f85c2f377d71935c7f0d208bacc52cf3dd531ae35c4b55a06ecadd989ceebbb9a34ddbfede06bf8f98ae70f6da63422db7f3
ssdeep: 1536:UuRTfwZ9MyJmfUk+g+pZgGEbGeftRkDhfdxoMqVjFeQJs:VRTwMsmfUWRJjs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DC33CEBB3640859CA885E342EFFC69F35F2F40F1E5B664E320C12699C51E302D29A57
sha3_384: ae5968349a764f0afc4e8285531cc2a1bc059582e2dc0f92a513afb9da9872ceea2c2af6c0b6ab8ef7e5321b42b8bad9
ep_bytes: 6830134000e8f0ffffff000000000000
timestamp: 1997-05-21 22:00:03

Version Info:

0: [No Data]

Win32:VB-ADBH [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.06FA1A22.A.FD1DD5B3
ClamAVWin.Trojan.VB-1627
CAT-QuickHealTrojan.Beebone.D
ALYacGeneric.Dacic.06FA1A22.A.FD1DD5B3
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.JorikGen.Win32.2
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.73a939
BaiduWin32.Worm.AutoRun.br
VirITWorm.Win32.VBDir.G
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AWG
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.egkt
BitDefenderGeneric.Dacic.06FA1A22.A.FD1DD5B3
NANO-AntivirusTrojan.Win32.Jorik.cinaxe
AvastWin32:VB-ADBH [Trj]
TencentTrojan.Win32.Jorik.kc
TACHYONTrojan/W32.VB-Jorik.126976.P
EmsisoftGeneric.Dacic.06FA1A22.A.FD1DD5B3 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner1.17382
VIPREGeneric.Dacic.06FA1A22.A.FD1DD5B3
TrendMicroTROJ_GEN.R002C0CFM23
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cz
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.7b11b8841d467263
SophosTroj/VB-FYF
IkarusWorm.Win32.Vobfus
GDataGeneric.Dacic.06FA1A22.A.FD1DD5B3
JiangminTrojan.Jorik.dcc
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitGeneric.Dacic.06FA1A22.A.FD1DD5B3
ViRobotTrojan.Win32.Agent.118784.GH
ZoneAlarmTrojan.Win32.Jorik.Vobfus.egkt
MicrosoftWorm:Win32/Vobfus.FI
GoogleDetected
AhnLab-V3Trojan/Win.Jorik.R526525
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36662.hmX@aWKTYNh
MAXmalware (ai score=84)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CFM23
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!YOl6U27bLhk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Jorik.EGLG!tr
AVGWin32:VB-ADBH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:VB-ADBH [Trj]?

Win32:VB-ADBH [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment