Malware

What is “Win32:VB-AEOA [Trj]”?

Malware Removal

The Win32:VB-AEOA [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-AEOA [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-AEOA [Trj]?


File Info:

name: D352694D8F45FA96672D.mlw
path: /opt/CAPEv2/storage/binaries/9c4fb45a39a49786fb3138c8c73fb02220b96dc1971b8b06eefec5ff21315a21
crc32: 8ED882DE
md5: d352694d8f45fa96672d94d1a5a5d5cd
sha1: 32d9a3bbfbe2eefe56627842fe2a55a8d82ce7cb
sha256: 9c4fb45a39a49786fb3138c8c73fb02220b96dc1971b8b06eefec5ff21315a21
sha512: d9cb7b3f5ac8d69ebe920e2aa0b82da15283cf0d910e5c658f824a626db653df3224a1c8504a523ccc812e171fded0be64b8e40461979266b1508b61698ee7b0
ssdeep: 1536:tEQ8p40DBeZUBFTgVjtXZTto1e9uCLBCPr8/NL44PerV5I8kIi/2O:ybp/eZU7TgdTq1ZrJO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183C3D53FBB529465E519293029F7C7F616BB6C1A2E0B505B6B0037BA4DB3F000C9DA67
sha3_384: b669212ca7415e13b893426de160843a84a9c33517152e139e7c0343c5699e3be97db1207d85e352c876a9964336e1be
ep_bytes: 689c134000e8eeffffff000000000000
timestamp: 2012-09-25 06:23:42

Version Info:

0: [No Data]

Win32:VB-AEOA [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431081
CAT-QuickHealWorm.VobfusMF.S28101913
SkyhighBehavesLike.Win32.Generic.ct
McAfeeVBObfus.dv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.431081
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
ArcabitTrojan.Barys.D693E9
BaiduWin32.Worm.Pronny.ew
VirITTrojan.Win32.Generic.GIZ
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.FQ
APEXMalicious
ClamAVWin.Trojan.VB-1720
KasperskyWorm.Win32.Vobfus.agxr
BitDefenderGen:Variant.Barys.431081
NANO-AntivirusTrojan.Win32.Autoruner.cinaru
AvastWin32:VB-AEOA [Trj]
TencentWorm.Win32.Vobfus.ky
EmsisoftGen:Variant.Barys.431081 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.26616
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d352694d8f45fa96
SophosML/PE-A
IkarusWorm.Win32.Vobfus
JiangminTrojan/Vbobf.b
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VB.HD.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.IVZ@4rktsd
MicrosoftWorm:Win32/Vobfus.IJ
ViRobotWorm.Win32.A.Vobfus.118784
ZoneAlarmWorm.Win32.Vobfus.agxr
GDataWin32.Trojan.PSE.56P7T0
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R37786
VBA32Worm.Vobfus
ALYacGen:Variant.Barys.431081
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!fYvWsAMx25M
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11612875.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36804.hmX@aeBxWJf
AVGWin32:VB-AEOA [Trj]
DeepInstinctMALICIOUS

How to remove Win32:VB-AEOA [Trj]?

Win32:VB-AEOA [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment