Home Malware Programs Viruses VirTool:Win32/VBInject.gen!CI

VirTool:Win32/VBInject.gen!CI

Posted: February 17, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 87
First Seen: December 7, 2010
Last Seen: October 2, 2018
OS(es) Affected: Windows

VirTool:Win32/VBInject.gen!CI is a Trojan threat that's able to download other infected programs onto your PC, reduce your security and steal personal information. Some versions of VirTool:Win32/VBInject.gen!CI are keyloggers, which can record keyboard input to steal passwords and related info. Others may be viruses as well as Trojans; virus-based VirTool:Win32/VBInject.gen!CI infections can corrupt existing files to avoid deletion and spread to new computers. No matter what type of VirTool:Win32/VBInject.gen!CI infection you have, this Trojan is a heavy risk to your privacy, security, and system stability. If you suspect your PC is infected with VirTool:Win32/VBInject.gen!CI, you should delete VirTool:Win32/VBInject.gen!CI with verified anti-malware applications.

VirTool:Win32/VBInject.gen!CI is a Trojan with Many Threats

Different types of VirTool:Win32/VBInject.gen!CI infections have been linked to some wildly different attacks, but most have had some baseline common traits, too. Since VirTool:Win32/VBInject.gen!CI is a Trojan, VirTool:Win32/VBInject.gen!CI has the built-in capability to download malware onto your machine and can change settings on your firewall and other security applications to supplement this. VirTool:Win32/VBInject.gen!CI will run whenever you start Windows, since VirTool:Win32/VBInject.gen!CI creates launch-enabling entries in your Registry that affect your PC whenever a normal startup process is done.

VirTool:Win32/VBInject.gen!CI is noted for being especially prominent in infected packages for pirate-related software such as crypters. However, VirTool:Win32/VBInject.gen!CI can be acquired from virtually any file from an insecure P2P network or free downloading website, or forced onto your computer through browser exploits.

Besides VirTool:Win32/VBInject.gen!CI's basic Trojan functions, any given instance of VirTool:Win32/VBInject.gen!CI may perform some or all of these attacks:

  • Backdoor security attacks. These types of attacks are used by backdoor Trojans like some versions of VirTool:Win32/VBInject.gen!CI to let remote attackers control your computer. The remote attacker can then steal information, force your PC to perform DDoS attacks, or cause direct damage to the system.
  • Keylogging. Some infections of VirTool:Win32/VBInject.gen!CI are keyloggers and will specifically look for passwords, account logins and other information. Besides looking for saved information, the infection can record everything you type on your keyboard, too. Game accounts are particularly targeted by some types of VirTool:Win32/VBInject.gen!CI.
  • In some cases, VirTool:Win32/VBInject.gen!CI is also a virus. Viruses can damage files on your computer by infecting them with malicious code, can spread easily to other computers and are often particularly difficult to get rid of.

...And Many Names to Go With VirTool:Win32/VBInject.gen!CI's Threats

VirTool:Win32/VBInject.gen!CI is also detected under several other names, such as Trojan-Dropper, Trojan.Win32.VB.vdt, Virus.Win32.VBInject and Trojan.Gen, depending on which scanners you use to catch VirTool:Win32/VBInject.gen!CI. Because the files used by VirTool:Win32/VBInject.gen!CI may be variable as well as hidden in your operating system folder, you should try to delete VirTool:Win32/VBInject.gen!CI with a good anti-malware product instead of removing the files yourself.

Until you've completely removed VirTool:Win32/VBInject.gen!CI from your PC, any information saved or typed is at risk of being leaked to hackers. Using a Safe Mode-based boot will let you stop VirTool:Win32/VBInject.gen!CI's process from defeating attempted deletions. If you scan once and don't see this threat even though you think VirTool:Win32/VBInject.gen!CI is there, make sure your scanner's threat database has the latest possible version. VirTool:Win32/VBInject.gen!CI isn't a very old Trojan as of yet, and may need to be dealt with by fully-updated software.

Aliases

Trj/Buzus.AH [Panda]Dropper.Generic2.UTR [AVG]W32/VBDrpr.AHT!tr [Fortinet]Mal/VBDrop-J [Sophos]TR/Agent.ahhtma [AntiVir]TrojWare.Win32.Trojan.VB.~CEJ [Comodo]Trojan.Agent.AQOB [BitDefender]Trojan-Dropper.Win32.VB.ahht [Kaspersky]Trojan.VB-19887 [ClamAV]Artemis!DE068F93A92D [McAfee]Win32.Trojan-Dropper.VB.ahht.3 [CAT-QuickHeal]Virus.Win32.VB [Ikarus]Heuristic.LooksLike.Trojan.Dropper.B [McAfee-GW-Edition]Win32:VB-OUL [Avast]Virus.Win32.VB!IK [a-squared]
More aliases (120)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\INSTALL\windows.exe File name: windows.exe
Size: 458.95 KB (458952 bytes)
MD5: 91ca0b3f640729d0d57382c2db74d153
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\INSTALL
Group: Malware file
Last Updated: February 24, 2011
C:\Extracted\2.exe File name: 2.exe
Size: 168.44 KB (168449 bytes)
MD5: 9a6bd44477c7c8f041f4af5d90e71c62
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: C:\Extracted
Group: Malware file
Last Updated: December 7, 2010
%APPDATA%\Net\Net.exe File name: Net.exe
Size: 434.37 KB (434376 bytes)
MD5: 6bac8607a77cfd50556afdd95bd8a3ac
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Net
Group: Malware file
Last Updated: October 2, 2018
C:\CNN\A\Lic.exe File name: Lic.exe
Size: 90.11 KB (90112 bytes)
MD5: d5d4cd3fa6e2497fbe8df31c4504883c
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: C:\CNN\A
Group: Malware file
Last Updated: December 6, 2011
%WINDIR%\Resources\sys.exe File name: sys.exe
Size: 454.85 KB (454856 bytes)
MD5: 23ee48a1315c6a56bf7a8014d66c4cc8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Resources
Group: Malware file
Last Updated: April 2, 2012
%SystemDrive%\dir\install\install\server.exe File name: server.exe
Size: 319.48 KB (319488 bytes)
MD5: de068f93a92d4d11206ca01fc585b46f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\dir\install\install
Group: Malware file
Last Updated: February 11, 2013
Loading...