Malware

Win32:VB-AEKP [Trj] information

Malware Removal

The Win32:VB-AEKP [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-AEKP [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-AEKP [Trj]?


File Info:

name: 3453A21CF9CB887FF106.mlw
path: /opt/CAPEv2/storage/binaries/5fb82f13257a68ac87444446230682f2b47a04ece41b414a92a40a23ad4bb448
crc32: 56F225B1
md5: 3453a21cf9cb887ff1064c2a15c3e000
sha1: 6f544b0fe8cf95cadcf533009e1799c74fb05085
sha256: 5fb82f13257a68ac87444446230682f2b47a04ece41b414a92a40a23ad4bb448
sha512: a264a28bc1925a643611fb67c2621ca7c78322c20bc54a5f2ee538e57fcabdd30d440cc983c9e30f1e745c20cb9d930acf92ca6ce46f391663a6c43c774eabb3
ssdeep: 3072:4OYyjGDDIVHbomqIQ7Dq7E0zQLQTAE5EG:4PIV7XqIAq7E0zQLgAET
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190D3C53BBE450856D91C61742BF6C7E102B3AC0BAA07522B971437AD2CA2F540D7CB6F
sha3_384: 1bd89d9851adee1cfaf6cdb966f7a80c0cc08a34be759f78543c4a445507777a15763d93351b2cfae558259a6fc07fb3
ep_bytes: 68d8124000e8eeffffff000000000000
timestamp: 2012-09-07 21:36:07

Version Info:

Translation: 0x0409 0x04b0
ProductName: aleochara
FileVersion: 1.21
ProductVersion: 1.21
InternalName: blameless
OriginalFilename: blameless.exe

Win32:VB-AEKP [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.3453a21cf9cb887f
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.950
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Pronny.ek
VirITTrojan.Win32.Generic.ARJ
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.DQ
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SM02
ClamAVWin.Trojan.VB-1604
KasperskyWorm.Win32.Vobfus.ole
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.VB.cmxslb
AvastWin32:VB-AEKP [Trj]
TACHYONWorm/W32.Vobfus.131072.C
SophosMal/SillyFDC-Y
F-SecureTrojan.TR/Barys.A.950
DrWebWin32.HLLW.Autoruner1.25602
TrendMicroWORM_VOBFUS.SM02
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.950 (B)
IkarusTrojan-Downloader.Win32.Beebone
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Barys.A.950
VaristW32/Vobfus.AQ.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.HR
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Barys.950
ZoneAlarmWorm.Win32.Vobfus.ole
GDataGen:Variant.Barys.950
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R35539
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.im0@aiATxKii
ALYacGen:Variant.Barys.950
MAXmalware (ai score=89)
VBA32Worm.VBNA
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!UE+Poba9A1w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4609109.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEKP [Trj]
Cybereasonmalicious.cf9cb8
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.6480a027

How to remove Win32:VB-AEKP [Trj]?

Win32:VB-AEKP [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment