Malware

Win32:VB-ADKF [Trj] information

Malware Removal

The Win32:VB-ADKF [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADKF [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-ADKF [Trj]?


File Info:

name: 80DB35C2E5D367C46CBD.mlw
path: /opt/CAPEv2/storage/binaries/ec871619e8b49069ea90730a72238dca3426ec80b3a7a88af991b015c66f3e44
crc32: 97BDA218
md5: 80db35c2e5d367c46cbd09d4953652ac
sha1: 21af1ebe18dd7294422dc509eb424fb5a5739f84
sha256: ec871619e8b49069ea90730a72238dca3426ec80b3a7a88af991b015c66f3e44
sha512: 794889d8e0b81a2a6ce5f3620bc6512eb4d066bde9c6521f91ed0f06029784098413bded130157761dcc6622463318b34343139459771424f56468ebcc395c41
ssdeep: 3072:JygdVAXY71idPAaRELGzMshNXTDFE+7jF6XTj+F:JygzAY+ocqFshNTDT756XTo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF0451256240E23DF020DAFD775442964DA86EB2D1D2A81BE2F8FB1137F4B5653B07A3
sha3_384: 1b81052554afdcaa66e6498c89db8051d76dd03fb9581f540bbf15a39cc55b638ec7262b1a621420086d5fde8c867683
ep_bytes: 68cc484000e8eeffffff000058000000
timestamp: 2012-06-19 07:41:52

Version Info:

Translation: 0x0409 0x04b0
Comments: Papillitis
CompanyName: Protostegidae Ejection
FileDescription: Fuye Actinocutitis
LegalCopyright: Seymour pseudolateral Reichsland
LegalTrademarks: Inexhaustibly palingenic
ProductName: Somatization ripiegasti
FileVersion: 6.05
ProductVersion: 6.05
InternalName: gwnvteeh
OriginalFilename: gwnvteeh.exe

Win32:VB-ADKF [Trj] also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Symmi.769
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Symmi.769
MalwarebytesVobfus.Worm.Evasion.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.2e5d36
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.Generic.ABKN
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AWV
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.cxya
BitDefenderGen:Variant.Symmi.769
NANO-AntivirusTrojan.Win32.Vobfus.ewqiln
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:VB-ADKF [Trj]
TencentWorm.Win32.Vobfus.n
Ad-AwareGen:Variant.Symmi.769
TACHYONWorm/W32.Vobfus.184320.C
EmsisoftGen:Variant.Symmi.769 (B)
ComodoWorm.Win32.VB.AUA@4o7zkg
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Symmi.769
TrendMicroWORM_VOBFUS.SMIV
McAfee-GW-EditionGenDownloader.oq
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.80db35c2e5d367c4
SophosML/PE-A + W32/Autorun-BXZ
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.769
JiangminTrojan/Vbobf.b
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.5
ArcabitTrojan.Symmi.769
ViRobotWorm.Win32.A.WBNA.184320.J
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftPWS:Win32/Zbot!ml
GoogleDetected
AhnLab-V3Worm/Win32.WBNA.R28275
McAfeeGenDownloader.oq
MAXmalware (ai score=80)
VBA32BScope.Trojan.VB.Onechki
CylanceUnsafe
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingWorm.Autorun!8.50 (TFE:3:ThNcPkzgh1O)
YandexTrojan.GenAsa!voQa7MUqIZQ
IkarusBackdoor.VB
MaxSecureWorm.WBNA.mwf
FortinetW32/VBKrypt.C!tr
BitDefenderThetaAI:Packer.4E1D8AA220
AVGWin32:VB-ADKF [Trj]
PandaW32/Vobfus.GEW.worm
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:VB-ADKF [Trj]?

Win32:VB-ADKF [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment