Malware

What is “Win32:VB-AIJU [Trj]”?

Malware Removal

The Win32:VB-AIJU [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-AIJU [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-AIJU [Trj]?


File Info:

name: 882DBEB50D1A8BAE2253.mlw
path: /opt/CAPEv2/storage/binaries/40cde75f51600d797af581af4ebe1b831f3ba0cd92b1bfa4aeb5d0717f0f179f
crc32: 182D850B
md5: 882dbeb50d1a8bae22533a2a229e1c0d
sha1: a6bbf805917077dcbbd90304665699ee7c840cad
sha256: 40cde75f51600d797af581af4ebe1b831f3ba0cd92b1bfa4aeb5d0717f0f179f
sha512: 03dd54f5213b1149fbc18dea125b05fd7c9c3a1ee6baa63c8009ad0613b61eb50e3173e6af21ec5f2fea5fa654c9df73fd22144747f196998b3d1ff87913a183
ssdeep: 3072:apjQXp5YHeNh1nm9JuKnvmb7/D26tvJc56bzfCKzg7bVuugHvmDwiBuAZd5:GjQ7LNh1wMKnvmb7/D26tBc5KDCKzg7f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF049516BA01A02FF59299F06D388BDA7C291D762780BC177781AF1466F149BB8F071F
sha3_384: 1c3cdf1f16cec99d3526b18bc29dd9d33ecf91aa07a7432a5542ac66135856bc11e11a933fb1a3e3594984ce6c0ce4c1
ep_bytes: 6844384000e8f0ffffff000000000000
timestamp: 2011-10-14 15:39:08

Version Info:

fg: er

Win32:VB-AIJU [Trj] also known as:

BkavW32.PolyVbJava.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.23
FireEyeGeneric.mg.882dbeb50d1a8bae
CAT-QuickHealWorm.VobfusVMF.S21686865
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.l
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.VBKrypt.23
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.SHeur4.EVS
SymantecW32.Changeup!gen15
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ANT
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMHF
AvastWin32:VB-AIJU [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.efmu
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.Vobfus.cqkygi
SUPERAntiSpywareTrojan.Agent/Gen-Vban
EmsisoftGen:Variant.VBKrypt.23 (B)
GoogleDetected
F-SecureTrojan.TR/Jorik.Vobfus.ibe
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMHF
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-T
IkarusTrojan.Spy.Agent
JiangminTrojan/Vbobf.b
VaristW32/Vobfus.AA.gen!Eldorado
AviraTR/Jorik.Vobfus.ibe
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBKrypt.23
ZoneAlarmWorm.Win32.Vobfus.efmu
GDataGen:Variant.VBKrypt.23
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R14477
Acronissuspicious
BitDefenderThetaAI:Packer.A2BDD2C920
ALYacGen:Variant.VBKrypt.23
TACHYONWorm/W32.Vobfus.176128.E
VBA32BScope.Trojan-Dropper.VB.01545
Cylanceunsafe
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!xs1LoISzfkY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.ADV!tr
AVGWin32:VB-AIJU [Trj]
PandaW32/Vobfus.GEW.worm
alibabacloudTrojan:Win/Vobfus.7a83ce6b

How to remove Win32:VB-AIJU [Trj]?

Win32:VB-AIJU [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment