Home Malware Programs Viruses Virus.Win32.VB.bu

Virus.Win32.VB.bu

Posted: September 8, 2011

Threat Metric

Threat Level: 7/10
Infected PCs: 61
First Seen: July 24, 2009
Last Seen: August 30, 2020
OS(es) Affected: Windows

Virus.Win32.VB.bu is a virus that steals private information by recording your keyboard input. Some versions of Virus.Win32.VB.bu may also perform other hostile actions such as disabling security alerts, Safe Mode or security-related programs. As a virus, Virus.Win32.VB.bu can also infect other files, which may damage these files or let Virus.Win32.VB.bu propagate across networks. Although there may be few or no signs that Virus.Win32.VB.bu is infecting your PC, any possibility of a Virus.Win32.VB.bu infection should be attended to immediately. Failing to remove Virus.Win32.VB.bu properly may result in any or all information on your computer being compromised.

Aliases

Trojan.VB.atv [eWido]Trojan.SystemPoser [Prevx1]TR/Agent.VB.H.22 [AntiVir]Trj/Passtealer.AW [Panda]Generic2.FRK [AVG]Trojan.Win32.Generic!BT [Sunbelt]Virus/Win32.VB.gen [Antiy-AVL]Trojan.Agent.VB.H [BitDefender]Worm.Win32.VB [K7AntiVirus]WORM_VB.DVP [TrendMicro]Infostealer.Lineage [Symantec]Troj/Gampass-A [Sophos]Medium Risk Malware [Prevx1]W32/VB.ADO [Panda]Win32/VB.NHZ [NOD32]
More aliases (47)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



G:\EXPLORER.EXE File name: EXPLORER.EXE
Size: 36.86 KB (36864 bytes)
MD5: 2971c53d6996c31cb1006161e1a66091
Detection count: 28
File type: Executable File
Mime Type: unknown/EXE
Path: G:\EXPLORER.EXE
Group: Malware file
Last Updated: October 27, 2021
EXPLORER.EXE File name: EXPLORER.EXE
Size: 36.86 KB (36864 bytes)
MD5: 8d22505c48ef1160b0518a662ae869b0
Detection count: 7
File type: Executable File
Mime Type: unknown/EXE
Group: Malware file
Last Updated: January 8, 2013
%WINDIR%\system32\EXPLORER.EXE File name: EXPLORER.EXE
Size: 36.86 KB (36864 bytes)
MD5: 36e44b719f44d4dd46f38f8e751b57b3
Detection count: 5
File type: Executable File
Mime Type: unknown/EXE
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 30, 2010
%Documents and Settings%\[UserName]\Application Data\av.exe File name: %Documents and Settings%\[UserName]\Application Data\av.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Documents and Settings%\[UserName]\Start Menu\ Protection Center.lnk File name: %Documents and Settings%\[UserName]\Start Menu\ Protection Center.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'tmp'HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon 'Shell' = '%UserProfile%\Application Data\antispy.exe'HKEY_CURRENT_USER\Software\Classes\secfileHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System 'DisableTaskMgr' = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings 'ProxyOverride' = ''HKEY_CURRENT_USER\Software\Malware Defense
Loading...