Malware

Win32:VB-RJW [Trj] malicious file

Malware Removal

The Win32:VB-RJW [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-RJW [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:VB-RJW [Trj]?


File Info:

name: A682801A71BE63C9A098.mlw
path: /opt/CAPEv2/storage/binaries/25731aaa03d7be007aee73870fe47b35b4800e66b91c061d6e764402ec0d617e
crc32: DC03DF60
md5: a682801a71be63c9a098e5cfee86ca7f
sha1: b84b6b0eaff78448f8e9bd0b082724c2a2239077
sha256: 25731aaa03d7be007aee73870fe47b35b4800e66b91c061d6e764402ec0d617e
sha512: ca9677be833f3d9bfdf55b7c3041d5a2839c5c29367ae6cce7dead69aa9e7c7f5e4bfa1172b0345ac078e1aa79ee3ae725a024c840b149073acacf4bb899ab96
ssdeep: 1536:CR3cftpPtbkuOL5vLJWnYlrbPMPXvPWPRPpPLCOzSo4BszKhyMee+FWMktOOqw9m:i3wDErlLCO14BiKhyMN+FPL/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13AA3722BB78110D7D51846B12DC7B7C655B232892A2735835B2016A7FC6AF420B7E8FF
sha3_384: 67694e1f8a9c76304c011f04beffc8656561bb348ecb2e61e043b0a97e1edcdcf7a3e9598588db83834246385d789b03
ep_bytes: 6840134000e8f0ffffff000000000000
timestamp: 2011-02-21 16:07:08

Version Info:

Translation: 0x0409 0x04b0
ProductName: OiDUMidvhSntwmDhp
FileVersion: 6.42
ProductVersion: 6.42
InternalName: oIXaPvUYyhj
OriginalFilename: oIXaPvUYyhj.exe

Win32:VB-RJW [Trj] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.97235
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.DoriMF.S26669771
ALYacTrojan.GenericKDZ.97235
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPRETrojan.GenericKDZ.97235
SangforTrojan.Win32.Save.a
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.a71be6
BaiduWin32.Worm.AutoRun.cj
VirITTrojan.Win32.Dorifel.WVU
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup!gen10
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ABI
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Dorifel.wvu
BitDefenderTrojan.GenericKDZ.97235
NANO-AntivirusTrojan.Win32.Dorifel.jpeofo
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
AvastWin32:VB-RJW [Trj]
TencentTrojan-Dropper.Win32.Dorifel.fa
TACHYONTrojan/W32.VB-Krypt.106496
EmsisoftTrojan.GenericKDZ.97235 (B)
F-SecureTrojan.TR/Dorifel.aqsza
DrWebTrojan.DownLoader2.15468
TrendMicroWORM_VOBFUS.SMIA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a682801a71be63c9
SophosMal/SillyFDC-C
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.97235
AviraTR/Dorifel.aqsza
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Vb.fmms@4rtl2e
ArcabitTrojan.Generic.D17BD3
ViRobotWorm.Win32.Generic.106496
ZoneAlarmTrojan-Dropper.Win32.Dorifel.wvu
MicrosoftWorm:Win32/Vobfus.DQ
GoogleDetected
AhnLab-V3Win-Trojan/VBKrypt.Gen
Acronissuspicious
McAfeeVBObfus.f
MAXmalware (ai score=88)
VBA32TrojanDropper.Dorifel
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!QU2XOJneHI0
IkarusTrojan.Win32.VBKrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
BitDefenderThetaAI:Packer.052CAE0220
AVGWin32:VB-RJW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:VB-RJW [Trj]?

Win32:VB-RJW [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment