Malware

Win32:VB-ADFI [Trj] removal tips

Malware Removal

The Win32:VB-ADFI [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADFI [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:VB-ADFI [Trj]?


File Info:

name: 4F06A31C59F33ABCDA5D.mlw
path: /opt/CAPEv2/storage/binaries/a9900ec39519d92b00bbef0abd7f08feef1560c71d55e85e094f46027927f407
crc32: D0F783CB
md5: 4f06a31c59f33abcda5dde85d3c5255d
sha1: 2f30aabd17aacd74952120255586e27674c02fd4
sha256: a9900ec39519d92b00bbef0abd7f08feef1560c71d55e85e094f46027927f407
sha512: 3db0db08f9e258e54121b4c1c49a2c79624c117c28d8465ba4b5a546f6e2239d367b072585f7069b51fbd2fdb6110d37c967ad86f7a73d2c69c07207c0310f59
ssdeep: 6144:6BawbQXn2J5V2aWOKojDOgbTnNkyjZjj+:6AwbQWoOKojDOgbTNku
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B44715523D0FB3CE424C2F829558250946AED3764A5AC0BFAD2BB5B77B1E47E260333
sha3_384: 1f80424429aae319485538da98c704fb0d4cd7dc3f0721fe06115b4cb872896384c74e08d347aa76346782cc00a74ce0
ep_bytes: 68844a4000e8eeffffff000000000000
timestamp: 2012-06-01 21:47:49

Version Info:

Translation: 0x0409 0x04b0
Comments: Play Station Nation v1
CompanyName: Play Station Nation v1
FileDescription: Play Station Nation v1
LegalCopyright: Play Station Nation v1
LegalTrademarks: Play Station Nation v1
ProductName: Play Station Nation v1
FileVersion: 36.00
ProductVersion: 36.00
InternalName: slrucrgj
OriginalFilename: slrucrgj.exe

Win32:VB-ADFI [Trj] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.luev
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.769
ClamAVWin.Trojan.Vobfus-24
FireEyeGeneric.mg.4f06a31c59f33abc
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Symmi.769
MalwarebytesWorm.Obfuscator
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Jorik.aa1d0df6
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.c59f33
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Generic.SPW
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/Pronny.AV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.epgn
BitDefenderGen:Variant.Symmi.769
NANO-AntivirusTrojan.Win32.Jorik.chvyyq
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ADFI [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Symmi.769 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Symmi.769
TrendMicroWORM_VOBFUS.SM42
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.moderate.ml.score
SophosMal/VBCheMan-J
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Symmi.769
JiangminWorm/Vobfus.abit
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Symmi.769
ViRobotTrojan.Win32.JORIK.262144.F
ZoneAlarmTrojan.Win32.Jorik.Vobfus.epgn
MicrosoftWorm:Win32/Vobfus.gen!R
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R28757
McAfeeVBObfus.ek
TACHYONTrojan/W32.Jorik.262144
VBA32BScope.Worm.WBNA
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM42
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!wsX8nu452bI
IkarusTrojan.Win32.Vobfus
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36196.qm0@auL93dki
AVGWin32:VB-ADFI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:VB-ADFI [Trj]?

Win32:VB-ADFI [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment