Malware

NewHeur_VB_Downloader.14 removal

Malware Removal

The NewHeur_VB_Downloader.14 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NewHeur_VB_Downloader.14 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

Related domains:

wpad.local-net
dxzj.org

How to determine NewHeur_VB_Downloader.14?


File Info:

name: F2B06A5083A1F60EA8A5.mlw
path: /opt/CAPEv2/storage/binaries/1a46891e06574b0fce6fa33522bce185c99d9ca8b181bfd13da9cf870d48daa2
crc32: FBED2BE5
md5: f2b06a5083a1f60ea8a55d1f81a9d530
sha1: 227c31519828cd5af207c70a29879ff3e5577cd8
sha256: 1a46891e06574b0fce6fa33522bce185c99d9ca8b181bfd13da9cf870d48daa2
sha512: 07906b1089927e9232e1ba999b8167ca73fc52dcf2f7988c7f67b7c67e9ab719551a3245d2d320acbeac5df1878ab225928b3d450ce5f01723fdb157119a74fe
ssdeep: 384:HTHRabww2JRm8OSE7EfAwBnQUXUoGWnOYeUAybgrKnGjDnssHT:HTHsaZNfFHUs8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162B26222F55CD03AF659C3F31E22C6D95156BE316A91ED0B39897F1E0D352C2A9E0B0B
sha3_384: ef2af3ac092b415c29df10e00dd6ae3a29f83f4d5036f7a2605c9a874261b0b686b9292accf5e6b126325d0a50ec8f47
ep_bytes: 6850144000e8eeffffff000000000000
timestamp: 2009-03-29 02:14:33

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 独轩之家
ProductName: 工程1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: UpData
OriginalFilename: UpData.exe

NewHeur_VB_Downloader.14 also known as:

MicroWorld-eScanTrojan.GenericKD.47480873
FireEyeTrojan.GenericKD.47480873
McAfeeArtemis!F2B06A5083A1
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 0057064f1 )
K7GWTrojan-Downloader ( 0057064f1 )
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderThetaGen:NN.ZevbaF.34294.bm0@aah9TZeb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of NewHeur_VB_Downloader.14
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.47480873
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.47480873
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.mz
IkarusTrojan.NewHeur_VB_Downloader
GDataTrojan.GenericKD.47480873
MicrosoftTrojan:Win32/Wacatac.B!ml
APEXMalicious
MAXmalware (ai score=86)
eGambitUnsafe.AI_Score_99%
AVGWin32:Trojan-gen
Cybereasonmalicious.19828c
PandaGeneric Malware

How to remove NewHeur_VB_Downloader.14?

NewHeur_VB_Downloader.14 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment