Malware

Win32:VB-ADPH [Trj] information

Malware Removal

The Win32:VB-ADPH [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADPH [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-ADPH [Trj]?


File Info:

name: 3BFEE635F73F3251029D.mlw
path: /opt/CAPEv2/storage/binaries/0c009513c8b10d6e8949411c1c425ae5b94d348a9cf0900cbb2c5a5c58530a6d
crc32: 4EEA8B11
md5: 3bfee635f73f3251029dc7f4ee677477
sha1: 69c4b1ded68e46bca145ff52b24a901002ae4307
sha256: 0c009513c8b10d6e8949411c1c425ae5b94d348a9cf0900cbb2c5a5c58530a6d
sha512: b0628895f874a6d54b11be5e086b88d7b85e9e1217ea3bd9a6661446a6733accfef60f2daee9c68a1366d2ca781401878faccccfeb0df38e9bb5a1481fe0232c
ssdeep: 1536:axEFgNOXsgnZ7QaI076EXJ/kMkRWnSRIsMFWFii3JXqkJZXLvDmNmond:1iOFKHNond
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C93D62CB7095067E6556BB82367CAC609BA6C0E5F0B604FA7047F6F2C34F800969B67
sha3_384: 64d9ffbd4aa828e6563a2686aa9df73030289664224de1a0346f59d6db886503b3427cf7dc67ac1a195be018c0aa9672
ep_bytes: 6888134000e8eeffffff000000000000
timestamp: 2012-07-04 19:05:32

Version Info:

Translation: 0x0409 0x04b0
Comments: Copriamo
CompanyName: Copriamo
FileDescription: Copriamo
LegalCopyright: Copriamo
LegalTrademarks: Copriamo
ProductName: Copriamo
FileVersion: 8.38
ProductVersion: 8.38
InternalName: Creedsman
OriginalFilename: Creedsman.exe

Win32:VB-ADPH [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vobfus.lx2G
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.VB.Agent.3
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.3bfee635f73f3251
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Heur.VB.Agent.3
MalwarebytesWorm.Obfuscator
ZillyaWorm.Vobfus.Win32.1194413
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaMalware:Win32/km_27b2.None
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.5f73f3
BaiduWin32.Worm.Pronny.ef
VirITTrojan.Win32.Cryptor.RR
CyrenW32/Vobfus.AX.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.BH
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.ipd
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.VB.covkdl
SUPERAntiSpywareTrojan.Agent/Gen-VBInject
AvastWin32:VB-ADPH [Trj]
RisingWorm.VobfusEx!1.99DB (CLASSIC)
TACHYONWorm/W32.VB-VBNA.94208.F
SophosMal/Kovter-W
F-SecureTrojan.TR/VB.Inject.11598
DrWebWin32.HLLW.Autoruner1.18425
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nm
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.VB.Agent.3 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VB.Agent.3
JiangminWorm.Vobfus.ptwg
AviraTR/VB.Inject.11598
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VB.Agent.3
ViRobotWorm.Win32.A.VBNA.94208.EC
ZoneAlarmWorm.Win32.Vobfus.ipd
MicrosoftWorm:Win32/Vobfus.FY
GoogleDetected
AhnLab-V3Worm/Win32.WBNA.R29524
McAfeeGeneric VB.jb
MAXmalware (ai score=86)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
TencentMalware.Win32.Gencirc.10b2022c
YandexTrojan.GenAsa!Qc4FyiYxk1s
IkarusVirus.Win32.Cryptor
MaxSecureTrojan.Malware.4785716.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36250.fm0@aW0UuLpi
AVGWin32:VB-ADPH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:VB-ADPH [Trj]?

Win32:VB-ADPH [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment