VBC FG-MU.dll threat report

MD5 f62eb86317de5f91176635e7b54b8d5e
Latest seen 2023-05-21 23:04:38 (2 years ago)
First seen 2019-07-07 11:18:32 (6 years ago)
Size 8 MB
Publisher Slate Digital
Product VBC FG-MU
Signed by Eiosis

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Heur!. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Heur!
Recommended action
Scan and remove
Last analysis
2023-05-21 23:04:38 (2 years ago)
File hash
f62eb86317de5f91176635e7b54b8d5e
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Heur!.

Timeline

First seen 2019-07-07 11:18:32 (6 years ago); latest analysis 2023-05-21 23:04:38 (2 years ago).

Publisher context

Company metadata: Slate Digital. Product metadata: VBC FG-MU.

Digital signature

Signed by Eiosis. The signature is not reported as trusted and valid, which can indicate tampering, repackaging, or copied publisher data.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

VBC FG-MU.dll is a Windows file recorded in the ThreatInfo database. It is associated with VBC FG-MU. The reported company name is Slate Digital. The current detection status is Trojan.Heur!, based on the latest analysis from 2023-05-21 23:04:38 (2 years ago).

If VBC FG-MU.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: VBC FG-MU
Company Name: Slate Digital
MD5: f62eb86317de5f91176635e7b54b8d5e
Size: 8 MB
First Published: 2019-07-07 11:18:32 (6 years ago)
Latest Published: 2023-05-21 23:04:38 (2 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2023-05-21 23:04:38 (2 years ago)
VBC FG-MU.dll detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

Signed By: Eiosis
Status: Invalid (digital signature could be stolen or file could be patched)

The signature on VBC FG-MU.dll is not reported as trusted and valid. Invalid or suspicious signature data can indicate tampering, repackaging, or an unrelated file using copied publisher information.

%sysdrive%\programs\plugins
%programfiles%\cakewalk\vstplugins
%programfiles%\vstplugins

ThreatInfo has observed VBC FG-MU.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

33.3%
33.3%
33.3%

The strongest geographic signal for this file is Ukraine with 33.3% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 66.7%
Windows 7 33.3%

The most common operating system signal for VBC FG-MU.dll is Windows 10 with 66.7% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

VBC FG-MU.dll is identified as pe for 64 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000500000000
Entry Address: 0x021a9200

PE Sections:

Name Size of data MD5
.text 2402304 9e045f1e875de1ad8fdcc71e4c7cfa59
IPPCODE 1228288 c1a7f12579d18ada4fb78e496255123d
.rdata 1746944 00600460875743116eb96553b33dd9de
.data 37888 c33d828ce518ebd865a0943eece3feb2
.pdata 280064 6757e2f476a2f58a292a9cd969f09566
.mfrt 512 912e20b1c98b0eed0cc4a6ad272540df
dummy1 512 f012d14427c96c563e019278ada2db4c
dummy2 512 2a430d72b420225e0d0604028c380a40
dummy3 512 b571e380d52461c8802a909999d84c05
dummy4 512 d7045561e2c015962a60bf6dbceadce7
.tls 512 8f560eb1391093271d44d71372d2c7d5
IPPDATA 3072 81d60e1f5be110ceba49410a7b99a880
.rsrc 1536 b8b6b6ad8bd820c5171d558182552209
.oldrel 66048 8dc66594b6c5739fe21867fd2bdefc75
.reloc64 257536 55e0dbd039472c7d450df96dad1547f1
.dogen 2441216 3cd7e67df059101742988274c40400f1
.dpack 4608 8f7e92f9ffad3354127cd10c99d10798

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: