Malware

Should I remove “Win32:VB-ADNO [Trj]”?

Malware Removal

The Win32:VB-ADNO [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADNO [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:VB-ADNO [Trj]?


File Info:

name: 640487B4F685D1430FA0.mlw
path: /opt/CAPEv2/storage/binaries/5e6e4d5aa77749bc8b47e49b4e5ad231d2e7fba1af7fe3d28c8c685d4e4aad43
crc32: 2896C5A3
md5: 640487b4f685d1430fa0efced820996f
sha1: 2e24e5d66c2e42e6e718aeea841fe5eaf99d6a5b
sha256: 5e6e4d5aa77749bc8b47e49b4e5ad231d2e7fba1af7fe3d28c8c685d4e4aad43
sha512: 9a2849c65b4916c460e9b64e8e10fa769cd9122e297eae0b0fb909c6d58016dba36af69b20e733dad3fc367bbe20a08ce82e33d43824b155a82e7ff5e4410934
ssdeep: 1536:g3j4EVT8JNenyIGmvcTlfbfwVocTzFJ0T72Vpcz:AxYhTxSBTzFJ0T72Qz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A930E1A77615422F70879723B43C7E339A76C4E9E1F91867744B9DB68A8E080C1DBE3
sha3_384: 8673f15828a34c62e74e4c03e9759291d00d3178b3c3ea35e945890004ef916bcae4911297aaf6d8f46d170966072d55
ep_bytes: 6824124000e8eeffffff000000000000
timestamp: 2012-06-29 22:39:21

Version Info:

Translation: 0x0409 0x04b0
Comments: Gastric
CompanyName: Gastric
FileDescription: Gastric
LegalCopyright: Gastric
LegalTrademarks: Gastric
ProductName: Gastric
FileVersion: 8.44
ProductVersion: 8.44
InternalName: Portless
OriginalFilename: Portless.exe

Win32:VB-ADNO [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lwz0
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.18337
MicroWorld-eScanGen:Heur.VB.Agent.3
FireEyeGeneric.mg.640487b4f685d143
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Heur.VB.Agent.3
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.VB.Agent.3
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_27b2.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.4f685d
BitDefenderThetaGen:NN.ZevbaF.36196.fm0@aaCXSFki
VirITWorm.Win32.X-Autorun.BBDH
CyrenW32/Vobfus.AT.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Pronny.BF
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.mxu
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.WBNA.cqkxzw
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ADNO [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Heur.VB.Agent.3 (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaWorm.WBNA.Win32.1536203
TrendMicroWORM_WBNA.SMD
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VB.Agent.3
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VB.Agent.3
ZoneAlarmWorm.Win32.WBNA.mxu
MicrosoftWorm:Win32/Vobfus.gen!W
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R48451
McAfeeVBObfus.n
TACHYONWorm/W32.WBNA.94208.B
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_WBNA.SMD
RisingWorm.VobfusEx!1.99E2 (CLASSIC)
YandexTrojan.GenAsa!WyUHhF5NCFg
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.4205716.susgen
FortinetW32/VBObfus.C!tr
AVGWin32:VB-ADNO [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:VB-ADNO [Trj]?

Win32:VB-ADNO [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment