Malware

About “Win32:VB-AEJB [Trj]” infection

Malware Removal

The Win32:VB-AEJB [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-AEJB [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-AEJB [Trj]?


File Info:

name: CD3F6282DE3F8D7E52E8.mlw
path: /opt/CAPEv2/storage/binaries/122a36d3925a0fcdd9c801de4d5a522bb6a7e09758ce0a83d83121a895c017a3
crc32: 2E2052DF
md5: cd3f6282de3f8d7e52e8d30fe0e03baa
sha1: 7086cdbb200700f035ffc3167779e4bca615b1da
sha256: 122a36d3925a0fcdd9c801de4d5a522bb6a7e09758ce0a83d83121a895c017a3
sha512: c232f37379fe14b317d81dceac55724381e65c43f286fab7e38bbafb127b04e74f996e6651e2e62fb243b8591cc6e1f9dbd33bc32e864cbcd88f605bb7872dd0
ssdeep: 3072:Y0Ax6LNxwqRXuD7mEVSuekhGkYrQRVZq3eFo4ejLnlQISQLpyhZu6qyK6YWVVDbf:tAxoNxTR82WGk1Y3nmQcuyKHWVVNt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191647561BF26FD83E049163ED3E98BF605452DFE2E06D2CBC631359A5AF1E170806636
sha3_384: 5aaca6e416592621270c4bc5f34f514c61ab2b17bd3516cf0ec054e69713b066e2c6bf375d67a908abd8090a46d999b9
ep_bytes: 6868134000e8f0ffffff000000000000
timestamp: 2012-09-01 17:32:56

Version Info:

Translation: 0x0409 0x04b0
ProductName: Periosteitis
FileVersion: 1.98
ProductVersion: 1.98
InternalName: isomyarian
OriginalFilename: isomyarian.exe

Win32:VB-AEJB [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.cd3f6282de3f8d7e
CAT-QuickHealTrojan.VobfusMF.S19994081
SkyhighBehavesLike.Win32.GenDownloader.fm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Pronny.gm
VirITTrojan.Win32.VB.ALK
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.DI
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SM02
ClamAVWin.Trojan.VB-1732
KasperskyTrojan.Win32.Vobfus.njf
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.VB.csnmnv
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AEJB [Trj]
TencentWorm.Win32.Vobfus.q
TACHYONTrojan/W32.VB-Vobfus.331776
SophosMal/Chuckee-E
GoogleDetected
F-SecureTrojan.TR/Barys.2644.91
DrWebTrojan.Siggen6.18938
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SM02
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Barys.950 (B)
IkarusTrojan-Dropper.Vb
JiangminTrojan/Vobfus.qly
VaristW32/VB.HD.gen!Eldorado
AviraTR/Barys.2644.91
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.988
MicrosoftWorm:Win32/Vobfus.HK
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.VBNA.331776.T
ZoneAlarmTrojan.Win32.Vobfus.njf
GDataGen:Variant.Barys.950
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R35238
Acronissuspicious
BitDefenderThetaAI:Packer.D746A1681F
ALYacGen:Variant.Barys.950
MAXmalware (ai score=88)
VBA32Trojan.VB.Marian
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!rmXDU4/U4uY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4454224.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AEJB [Trj]
Cybereasonmalicious.2de3f8
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.5f9d3fe6

How to remove Win32:VB-AEJB [Trj]?

Win32:VB-AEJB [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment