Home Malware Programs Viruses VBInject.gen!EP

VBInject.gen!EP

Posted: March 14, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 80
First Seen: March 14, 2011
OS(es) Affected: Windows

VirTool:Win32/VBInject.gen!EP is a virus that uses advanced techniques in order to change program codes of modified objects in computer memory. VirTool:Win32/VBInject.gen!EP is able to evade detection and removal of many security applications. VirTool:Win32/VBInject.gen!EP is composed of a loader developed using Visual Basic and the content it brings out into the infected computer system. The loader keeps the downloaded object encrypted and injects it into a new process or generates a completely new one to run the malicious code. The encoded file is not copied on the disk.

Aliases

Bck/Bifrost.gen [Panda]VB.BMGG [AVG]Trojan-Dropper.Win32.Bifrose [Ikarus]Win-Trojan/Refroso.409981.J [AhnLab-V3]Win32/Bifrose.F!generic [eTrust-Vet]TR/Dropper.Gen [AntiVir]BackDoor.Bifrost.14965 [DrWeb]Mal/Generic-L [Sophos]Trojan.Generic.6458232 [BitDefender]Trojan.Win32.VBKrypt.fkxr [Kaspersky]Trojan.VB-45359 [ClamAV]Trojan.ADH.2 [Symantec]a variant of Win32/Bifrose.NLE [NOD32]Generic VB.fl [McAfee]Trojan/Win32.Refroso [AhnLab-V3]
More aliases (144)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Microsoft\Internet Explorer\checkdiska.exe File name: checkdiska.exe
Size: 53.24 KB (53248 bytes)
MD5: 367c7b04e59708aaf64f502ce526fad8
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Internet Explorer
Group: Malware file
Last Updated: December 24, 2012
%WINDIR%\system32\spynet\msnmsg.EXE File name: msnmsg.EXE
Size: 385.11 KB (385117 bytes)
MD5: a084cff85b61a48400ca19304f77136c
Detection count: 55
File type: Executable File
Mime Type: unknown/EXE
Path: %WINDIR%\system32\spynet
Group: Malware file
Last Updated: March 14, 2011
%ALLUSERSPROFILE%\0af6e1\IS0af_289.exe File name: IS0af_289.exe
Size: 6.13 MB (6130176 bytes)
MD5: 5b04fd24d9296b9144d18942d78ddb52
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\0af6e1
Group: Malware file
Last Updated: March 15, 2011
%APPDATA%\NBYBVXISEUQ.exe File name: NBYBVXISEUQ.exe
Size: 111.1 KB (111104 bytes)
MD5: 7f832a89fb9cac8acb850ed5ba8de539
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 17, 2011
%USERPROFILE%\winlogon.exe File name: winlogon.exe
Size: 42.49 KB (42496 bytes)
MD5: 053a8261f2ccba072b033803adc4523e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: April 15, 2011
%APPDATA%\InstallDir\Server.exe File name: Server.exe
Size: 449.53 KB (449536 bytes)
MD5: 4eaf5e925f149b080d8194e2162e416e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\InstallDir
Group: Malware file
Last Updated: April 8, 2013
Loading...