Malware

Win32:VB-ADTK [Trj] removal instruction

Malware Removal

The Win32:VB-ADTK [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ADTK [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-ADTK [Trj]?


File Info:

name: 0B996AC9AA45ECDCD0F0.mlw
path: /opt/CAPEv2/storage/binaries/249f3bbfd263bbb452c97347da54c08e057ba6f0767aaab285c199fed5c97a36
crc32: F082EF0B
md5: 0b996ac9aa45ecdcd0f000ec4cfe3fbb
sha1: 2c720752730be5758897ceaccf7cfa3c0f9bca71
sha256: 249f3bbfd263bbb452c97347da54c08e057ba6f0767aaab285c199fed5c97a36
sha512: e0dcd87b2a14a76f515bd1ba32867f7f3e24bfda64d310982ddfa2d20f87e0b32d0de26f79ad0f860c6c20a920b7fbfd099dbb3eb6735cead2e7c4d5ffb7b47c
ssdeep: 1536:DNIEc5HBkoNhTOWhcPYZxAxMpBd48CArrprb42:pIDHNhTOWhcAZxAulB42
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F683A55B7F40C069E725697C27FAC3E615E7689E5A0B150BB6003B694CDBF240A1CEB3
sha3_384: f8ed8a0d662d131ce50606f8d180d8bd6a545221cd0d670e68f51743ec3a4e2dd96bac6582a8b6718716a5f80e5bc94b
ep_bytes: 6870124000e8f0ffffff000000000000
timestamp: 2012-07-18 20:04:49

Version Info:

Translation: 0x0409 0x04b0
Comments: taslet dinergate
CompanyName: taslet dinergate
FileDescription: taslet dinergate
LegalCopyright: taslet dinergate
LegalTrademarks: taslet dinergate
ProductName: taslet dinergate
FileVersion: 1.48
ProductVersion: 1.48
InternalName: forespeed
OriginalFilename: forespeed.exe

Win32:VB-ADTK [Trj] also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-ADTK [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.30988
MicroWorld-eScanGen:Variant.Barys.5614
FireEyeGeneric.mg.0b996ac9aa45ecdc
CAT-QuickHealWorm.WbnaMF.S21116094
SkyhighBehavesLike.Win32.VBObfus.mm
McAfeeGenDownloader.pr
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005640b91 )
K7GWTrojan ( 004e173b1 )
BitDefenderThetaAI:Packer.1F28EE6920
VirITTrojan.Win32.Cryptor.OT
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.BM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.VBNA.bang
BitDefenderGen:Variant.Barys.5614
NANO-AntivirusTrojan.Win32.VB.covket
AvastWin32:VB-ADTK [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Barys.5614 (B)
F-SecureTrojan.TR/Barys.568879
BaiduWin32.Worm.Pronny.ep
VIPREGen:Variant.Barys.5614
TrendMicroWORM_VOBFUS.SM01
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
JiangminWorm.VBNA.qkd
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Barys.568879
MAXmalware (ai score=81)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.998
MicrosoftWorm:Win32/Vobfus.HF
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Barys.D15EE
ViRobotWorm.Win32.A.VBNA.86016.GG
ZoneAlarmWorm.Win32.VBNA.bang
GDataGen:Variant.Barys.5614
VaristW32/Vobfus.AT.gen!Eldorado
AhnLab-V3Worm/Win32.VBNA.R32380
Acronissuspicious
ALYacGen:Variant.Barys.5614
VBA32Worm.VBNA
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!B646mKtnqE0
IkarusVirus.Win32.VB
MaxSecureTrojan.Malware.4278977.susgen
FortinetW32/Injector.ADYA!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.5541bad0

How to remove Win32:VB-ADTK [Trj]?

Win32:VB-ADTK [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment