Malware

Win32:VB-ADMV [Trj] removal guide

Malware Removal

The Win32:VB-ADMV [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADMV [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-ADMV [Trj]?


File Info:

name: D4FD952BE391CA3CC5EA.mlw
path: /opt/CAPEv2/storage/binaries/88642500e1fc339392b8b62c8e15859a591b6083884f90bbe8f59e97be1aa236
crc32: 662805D3
md5: d4fd952be391ca3cc5ea02d813a79e11
sha1: c3e8860812c8104b3e204c5cceb9803d6ca2e83c
sha256: 88642500e1fc339392b8b62c8e15859a591b6083884f90bbe8f59e97be1aa236
sha512: cdabd47c862737c4f3f940dc2508c99764ad3b57cb066feaa903bd1f14a5608ad1dfaccdc72774445f6ecd4186124c95be1a8534f9d94bcc4b6d70bf8d33dc55
ssdeep: 1536:8Fpy9ddd7Y1idNzL7zdddXOpdxCTkQjW/dQqdUxpkddAd3nddd4od5ddMk5dSt2w:CrSzBLKBTzFJ0T72er6lQhaWe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FD392D671C1D46DC57CDF3C23DE86F23DE56A0BA50B196FE320AF245C62A182760A72
sha3_384: 30e7a625a5c4393265c1a1eb821bcfa323b9827f13aff0ee1e89f1a97f2bad715140630b30552da5b3c700ea718c7273
ep_bytes: 6820124000e8f0ffffff000000000000
timestamp: 2002-06-15 03:02:37

Version Info:

0: [No Data]

Win32:VB-ADMV [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.97415
FireEyeGeneric.mg.d4fd952be391ca3c
CAT-QuickHealTrojan.Beebone.D
ALYacTrojan.GenericKDZ.97415
Cylanceunsafe
VIPRETrojan.GenericKDZ.97415
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.97415
K7GWTrojan ( 004cadc41 )
K7AntiVirusTrojan ( 004cadc41 )
ArcabitTrojan.Generic.D17C87
BitDefenderThetaGen:NN.ZevbaF.36196.imX@aWzG7Kb
VirITWorm.Win32.X-Autorun.BAUV
CyrenW32/VB.ZN.gen!Eldorado
SymantecW32.Changeup!gen20
ESET-NOD32a variant of Win32/Pronny.BE
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.LokiBot-9866840-0
KasperskyTrojan.Win32.Jorik.Vobfus.eyoe
NANO-AntivirusTrojan.Win32.Jorik.cfdsms
RisingTrojan.VB!1.99F7 (CLASSIC)
TACHYONTrojan/W32.VB-Jorik.135168.E
SophosMal/SillyFDC-Y
BaiduWin32.Worm.Autorun.w
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner1.18117
TrendMicroTROJ_GEN.R03BC0CEN23
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.97415 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUC@4omkmv
MicrosoftWorm:Win32/Vobfus.gen!W
ZoneAlarmTrojan.Win32.Jorik.Vobfus.eyoe
GDataWin32.Trojan.PSE.1IGMVDB
GoogleDetected
Acronissuspicious
McAfeeVBObfus.n
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
VBA32Trojan.Vobfus
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_GEN.R03BC0CEN23
TencentTrojan.Win32.Vobfus.hcq
YandexTrojan.GenAsa!0Ax3ct62bfs
IkarusTrojan-Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.C!tr
AVGWin32:VB-ADMV [Trj]
Cybereasonmalicious.be391c
AvastWin32:VB-ADMV [Trj]

How to remove Win32:VB-ADMV [Trj]?

Win32:VB-ADMV [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment