Malware

About “Win32:VB-ADOU [Trj]” infection

Malware Removal

The Win32:VB-ADOU [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADOU [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-ADOU [Trj]?


File Info:

name: 08A5D2D5278762E9DA44.mlw
path: /opt/CAPEv2/storage/binaries/3d66f3532fe598114d483bfa89f6255e2cdd7c02c5d5169ecf3bb79087d4b1f3
crc32: BE276CD5
md5: 08a5d2d5278762e9da444a11cdb4e551
sha1: 69a9e392bc9104845015767247d1888facee4ae8
sha256: 3d66f3532fe598114d483bfa89f6255e2cdd7c02c5d5169ecf3bb79087d4b1f3
sha512: d0713d0586887c270697e58e4379efb45a07542e58bef6574c6c8c217825302c3930fd1044a80df93ab52f081f1d0486b05d7b6600c62057475ddfc1a114e0f9
ssdeep: 3072:/Lyt4k1iZKuPxqAXDdwCKYcQ+gqNAUjigdN:/L1QATOX9NZBd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C904C5367790A67EC011D7F82C6F8350806DAC3811EAFA13F6D26A56B6F29779364343
sha3_384: f65e012579f735b07f4cd03ccca3a9239b30e3d7a92bdd9736962440130cace9ba504eba78d8a688942751af807c20f4
ep_bytes: 6894454000e8eeffffff000000000000
timestamp: 2012-07-03 12:11:42

Version Info:

Translation: 0x0409 0x04b0
Comments: Superlabial
CompanyName: Superlabial
FileDescription: Superlabial
LegalCopyright: Superlabial
LegalTrademarks: Superlabial
ProductName: Superlabial
FileVersion: 0.59
ProductVersion: 0.59
InternalName: distraught
OriginalFilename: distraught.exe

Win32:VB-ADOU [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vobfus.lx2G
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.08a5d2d5278762e9
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.df
Cylanceunsafe
VIPREGen:Variant.VBInject.11
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.ba78fa90
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.527876
BitDefenderThetaGen:NN.ZevbaF.36250.km0@aifq1agi
VirITWorm.Win32.Generic.CDST
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup!gen18
ESET-NOD32a variant of Win32/AutoRun.VB.AXG
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.erzs
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.WBNA.cmxrip
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ADOU [Trj]
TencentMalware.Win32.Gencirc.10b0ded3
EmsisoftGen:Variant.VBInject.11 (B)
BaiduWin32.Trojan.VBObfus.f
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.moderate.ml.score
SophosMal/VBCheMan-J
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.VBInject.11
JiangminWorm/WBNA.dgmt
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBInject.11
ViRobotWorm.Win32.A.WBNA.176128.AF
ZoneAlarmWorm.Win32.Vobfus.erzs
MicrosoftTrojan:Win32/Meredrop
GoogleDetected
AhnLab-V3Worm/Win32.WBNA.R29524
VBA32BScope.Trojan.Diple
ALYacGen:Variant.VBInject.11
MAXmalware (ai score=85)
MalwarebytesWorm.Obfuscator
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.AutoRun!1.E3CB (CLASSIC)
YandexTrojan.GenAsa!8fs7I17oTMA
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.4231562.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ADOU [Trj]
DeepInstinctMALICIOUS

How to remove Win32:VB-ADOU [Trj]?

Win32:VB-ADOU [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment