Malware

Win32:VB-ADGR [Trj] (file analysis)

Malware Removal

The Win32:VB-ADGR [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADGR [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-ADGR [Trj]?


File Info:

name: EACC3451CE01A393A82B.mlw
path: /opt/CAPEv2/storage/binaries/ebb79f4ae8d947d467e2ff272955aeddcca57051f1f9c8ba3e3bd76ef0e80b83
crc32: FA578431
md5: eacc3451ce01a393a82bd976c7146c7b
sha1: e58fe81f752ebdaadc10719b03ed397575dc38fa
sha256: ebb79f4ae8d947d467e2ff272955aeddcca57051f1f9c8ba3e3bd76ef0e80b83
sha512: 243dded1ad1eb3f62286730662d8db7c8368b5ca778cdf518da67a4fd86c4e09ded5d3ee753f365483d63f826aa387c9b67023fde8c0784d239c94738b17f4b1
ssdeep: 3072:xE4rrMwwKsPUTVY7fhINP7JsfLBsyVEJ8Ixjtmkp44upWuTNgX8Tjee/L1pwW6gr:mMesgfuNPK5VEVtmk4DAuTxeOwu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10644711523D0FB39E424C6F92A558350C16FEC3224A4BC1BF6D26B4B7BA1D67E661323
sha3_384: 6ac4c90ece815aaa75bbe4af7453f6098d0286d11c9d9e47b63b56cbdd4f45a768d96d71a9d1e55f7474ffaaa755e8b6
ep_bytes: 6824524000e8eeffffff000058000000
timestamp: 2012-06-05 06:12:48

Version Info:

Translation: 0x0409 0x04b0
Comments: tungsten Terreni jargonesque
CompanyName: Passionwort
FileDescription: reckling autacoid Spalmiate
LegalCopyright: bibliographically terbic siliconized
LegalTrademarks: asexualization Trochocephaly chumpaka
ProductName: Assimilability Phantasmagoria
FileVersion: 55.00
ProductVersion: 55.00
InternalName: hnsyftbfdrpqra
OriginalFilename: hnsyftbfdrpqra.exe

Win32:VB-ADGR [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.769
FireEyeGeneric.mg.eacc3451ce01a393
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.Symmi.769
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1523177
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Vobfus.036b3a41
K7GWTrojan ( 005640b91 )
K7AntiVirusTrojan ( 005640b91 )
BitDefenderThetaGen:NN.ZevbaF.36802.qm0@a8bkLDoi
VirITTrojan.Win32.Zyx.LC
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AWO
APEXMalicious
AvastWin32:VB-ADGR [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.ersj
BitDefenderGen:Variant.Symmi.769
NANO-AntivirusTrojan.Win32.Jorik.cmtirq
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
TencentWorm.Win32.Vobfus.kg
EmsisoftGen:Variant.Symmi.769 (B)
BaiduWin32.Worm.Pronny.d
F-SecureWorm.WORM/Vobfus.oeinajo
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Symmi.769
TrendMicroWORM_VOBFUS.SM01
SophosMal/SillyFDC-W
MAXmalware (ai score=87)
WebrootTrojan.Win32.Diple
GoogleDetected
AviraWORM/Vobfus.oeinajo
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Symmi.769
ViRobotWorm.Win32.A.WBNA.274432.EG
ZoneAlarmWorm.Win32.Vobfus.ersj
GDataGen:Variant.Symmi.769
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R27224
Acronissuspicious
McAfeeVBObfus.ek
TACHYONTrojan/W32.Agent.274432
VBA32BScope.Trojan.Diple
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.Vobfus!8.10E (TFE:3:fEb97LT8bQJ)
YandexTrojan.GenAsa!tAYezjw7i9w
IkarusTrojan.Win32.Meredrop
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ADGR [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.a18bab0d

How to remove Win32:VB-ADGR [Trj]?

Win32:VB-ADGR [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment