Backdoor

NewHeur_VB_Backdoor.2 removal guide

Malware Removal

The NewHeur_VB_Backdoor.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NewHeur_VB_Backdoor.2 virus can do?

  • Executable code extraction
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine NewHeur_VB_Backdoor.2?


File Info:

crc32: 58CE76C7
md5: 23f9eccca7762a4c24ad2b2170815183
name: 23F9ECCCA7762A4C24AD2B2170815183.mlw
sha1: ee51170a35fcf0406ec4bd06b038ec8510b45938
sha256: 1e08d30cf776a188e2f44172fb2e99e0a0ec62d2e8a11f33e536e911a9408696
sha512: a38bcee1048e6ad80a1ac0b5b5bdae7f388c82ef895f038f33f1ba014db2adc7064f53bc00e03d7fe0a553d8ee92d69bbbae4c34362c9ff7bac7b12f2cf53e93
ssdeep: 1536:n8jCuakzVMw/2bYbOg6CbHe6fcBr1Epv3E6RwYRzVbbrU5ItbRdnXM4f:8jd1zVh/2bY362HeUcBUU6HbU5IhRn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
InternalName: svchost
FileVersion: 1.03
CompanyName: IndiSof Corporation
ProductName: REMOTE CONTROL 1.2
ProductVersion: 1.03
OriginalFilename: svchost.exe

NewHeur_VB_Backdoor.2 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusP2PWorm ( 0046b2151 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop8.1833
ALYacGen:Trojan.Heur.RX.fm0@XKvpTLpG
CylanceUnsafe
ZillyaTrojan.VB.Win32.177634
SangforTrojan.Win32.VB.8
K7GWP2PWorm ( 0046b2151 )
Cybereasonmalicious.ca7762
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of NewHeur_VB_Backdoor.2
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Xkvptlpg-9848791-0
BitDefenderGen:Trojan.Heur.RX.fm0@XKvpTLpG
NANO-AntivirusTrojan.Win32.VB.eywdqw
MicroWorld-eScanGen:Trojan.Heur.RX.fm0@XKvpTLpG
TencentWin32.Trojan.Heur.Hssv
Ad-AwareGen:Trojan.Heur.RX.fm0@XKvpTLpG
SophosMal/Generic-R + Mal/Behav-035
ComodoMalware@#fmwfvhte0l8j
BitDefenderThetaAI:Packer.E3A12BB31F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
FireEyeGen:Trojan.Heur.RX.fm0@XKvpTLpG
EmsisoftGen:Trojan.Heur.RX.fm0@XKvpTLpG (B)
AviraTR/ATRAPS.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Heur.RX.EF5C81
GDataGen:Trojan.Heur.RX.fm0@XKvpTLpG
McAfeeArtemis!23F9ECCCA776
MAXmalware (ai score=94)
PandaTrj/GdSda.A
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.OLY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove NewHeur_VB_Backdoor.2?

NewHeur_VB_Backdoor.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment