Malware

Win32:VB-ZPS [Trj] removal guide

Malware Removal

The Win32:VB-ZPS [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-ZPS [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:VB-ZPS [Trj]?


File Info:

name: 4339142C9B4089766D71.mlw
path: /opt/CAPEv2/storage/binaries/1311fafe2354c68dfe6f097362a1c8188c311abc9c6ea55c869125b13ee1133b
crc32: 7278A3CA
md5: 4339142c9b4089766d71574a86cd47fb
sha1: f630db75c887a79ce68512cb83f4a866c9c0b468
sha256: 1311fafe2354c68dfe6f097362a1c8188c311abc9c6ea55c869125b13ee1133b
sha512: 06864ce502f7307b0da5d49253ee42d85f832ce3c1ff56fb2b47c968cf7d75086f673d46633f4088eb9b21c764570df94b756215fc4c927114b3515d557614e4
ssdeep: 6144:8T2dFiVGBngFg4S628gA/igGuncMkcH/AeKnvmb7/D26ppSgCbvfEJ:Q2PigBnga4S628dFncMkcHIeKnvmb7/9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18344A4136A25A41FE64689F01D5E97967C382C3726906C03B3C17F2D65706ABB8F13AF
sha3_384: 5a1f1f7febf5605d8df132aaebc2d4ac1ffbc3a1aeb0d6f123b3b2fccf31a98c048baf0d2bf58148a92b1307e003f477
ep_bytes: 6850394000e8eeffffff000000000000
timestamp: 2011-11-09 06:00:49

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:

Win32:VB-ZPS [Trj] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.luev
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.77
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.4339142c9b408976
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.Barys.950
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Agent2.Win32.21969
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Barys.950
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.5c887a
BitDefenderThetaGen:NN.ZevbaF.36792.pm0@aGW1Uqgi
VirITWorm.Win32.Generic.BCJR
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.APA
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Agent2.eohv
AlibabaWorm:Win32/Vobfus.b8bb75cc
NANO-AntivirusTrojan.Win32.WBNA.csfhkv
ViRobotTrojan.Win32.Agent.258048.Q
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.VB-Agent2.258048
SophosMal/SillyFDC-T
GoogleDetected
F-SecureWorm.WORM/Autorun.JG.1
BaiduWin32.Worm.Autorun.l
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SMAB
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Barys.950 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Diple.Gen
VaristW32/Vobfus.Z.gen!Eldorado
AviraWORM/Autorun.JG.1
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.gen!O
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.950
SUPERAntiSpywareTrojan.Agent/Gen-Autogen
ZoneAlarmTrojan.Win32.Agent2.eohv
GDataGen:Variant.Barys.950
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R16325
Acronissuspicious
McAfeeVBObfus.cm
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99D9 (CLASSIC)
YandexTrojan.GenAsa!l59GvDrsJdg
IkarusTrojan.Win32.Otran
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-ZPS [Trj]
AvastWin32:VB-ZPS [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:VB-ZPS [Trj]?

Win32:VB-ZPS [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment