Malware

Win32:VB-UKD [Trj] removal instruction

Malware Removal

The Win32:VB-UKD [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-UKD [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:VB-UKD [Trj]?


File Info:

name: 6A0A94C419F4C14029F4.mlw
path: /opt/CAPEv2/storage/binaries/9e7479ac86e3a140e4b5e52bf179757b263190e8bc5bfb796b38e304c54e1ecb
crc32: E5727D9E
md5: 6a0a94c419f4c14029f43e4bfc011ac6
sha1: 5a0b8ef584f4dd8928aab503cd351ec681c20ffd
sha256: 9e7479ac86e3a140e4b5e52bf179757b263190e8bc5bfb796b38e304c54e1ecb
sha512: dacd0c550694cb91bc246a7ad8533a858aa7ace1f375b8e93907f9d906d1cee5587c31046bc5fdba634c69b3bb92b26c5d3229c4099e4a5a9ac9df6679bae069
ssdeep: 6144:x+AxyrimEU/EztV++Jbtd4lfn8hFXbTom85FMnH:xNErimr/EztV++JZd4lfnSTo7F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F441C26E620A03AF98784F6B069E39A340C2D7507D1EC07B7856B95B0B42D7F5F261F
sha3_384: 97fc839c2e59c9f94cd4eedf82e74b4a11c31186259b789e78bfa929195938c7fccc5d31283dd83f686a02ee73d74985
ep_bytes: 68d03e4000e8f0ffffff000000000000
timestamp: 2011-06-01 02:44:08

Version Info:

Translation: 0x0409 0x04b0
ProductName: bavkvvVbM
FileVersion: 1.00
ProductVersion: 1.00
InternalName: IEQxTwPBVByqXa
OriginalFilename: IEQxTwPBVByqXa.exe

Win32:VB-UKD [Trj] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lr3L
DrWebTrojan.VbCrypt.60
CynetMalicious (score: 100)
FireEyeGeneric.mg.6a0a94c419f4c140
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.g
Cylanceunsafe
VIPREGen:Variant.Chinky.6
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.5d47ae6f
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.419f4c
BitDefenderThetaAI:Packer.48CE1FE120
VirITTrojan.Win32.SHeur3.CCGQ
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AZK
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.apc
BitDefenderGen:Variant.Chinky.6
NANO-AntivirusTrojan.Win32.WBNA.eihzwi
MicroWorld-eScanGen:Variant.Chinky.6
AvastWin32:VB-UKD [Trj]
TencentWorm.Win32.WBNA.hn
TACHYONTrojan/W32.VB-VBKrypt.258048.J
EmsisoftGen:Variant.Chinky.6 (B)
F-SecureWorm.WORM/Vobfus.CF.27
BaiduWin32.Worm.Autorun.l
TrendMicroWORM_VBNA.SMED
Trapminemalicious.moderate.ml.score
SophosMal/VB-XV
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.W.gen!Eldorado
AviraWORM/Vobfus.CF.27
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.997
MicrosoftWorm:Win32/Vobfus.CF
XcitiumWorm.Win32.Vobfus.E@3unn0h
ArcabitTrojan.Chinky.6
ZoneAlarmWorm.Win32.WBNA.apc
GDataGen:Variant.Chinky.6
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R15972
Acronissuspicious
VBA32Malware-Cryptor.VB.gen
ALYacGen:Variant.Chinky.6
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEP
TrendMicro-HouseCallWORM_VBNA.SMED
RisingWorm.AutoRun!8.197D5 (CLOUD)
YandexTrojan.GenAsa!bt6veHZZNC8
IkarusGen.Variant.Chinky
FortinetW32/VB.ADV!tr
AVGWin32:VB-UKD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan.Win.UnkAgent

How to remove Win32:VB-UKD [Trj]?

Win32:VB-UKD [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment