Malware

NewHeur_VB_Downloader.3 removal

Malware Removal

The NewHeur_VB_Downloader.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NewHeur_VB_Downloader.3 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

safe.ywxww.net
icafe8.kf5.com
www.bing.com
ocsp.digicert.com
status.rapidssl.com

How to determine NewHeur_VB_Downloader.3?


File Info:

crc32: A701ADF3
md5: 63399c74c5dda6fa8276ded35b5118b9
name: bxn.exe
sha1: 851d0792a3bd617846f27a55b77058ddc8a83890
sha256: d121605217cfec4a341b4b889ec374d6bc0be6b93886e4a6788865f9022be50a
sha512: 7e5524e7c75030b98c53aeadc3d6f6a45c3167fd7f9aeb2029670f619b36bb848822a8f457bc6b696c88115229f7b2bea6da8e2398bcfaf8dd48ffc253cebaa5
ssdeep: 768:P45UMrFV1yQlNBqHpBtzs2N77F/WTI+owQ:UJrFV1yQlzqztzsJo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: x5728x7ebfx62a5x4fee
FileVersion: 1.01.0006
CompanyName: x4e49x4e4cx65b0x7f51x7ef4
Comments: x66f4x6362x53d1x4ef6x8d26x53f7xff0cx6dfbx52a0x7f51x7ba1x5de5x5177x63a5x53e3xff0cx4feex6b63x5185x7f51IPx83b7x53d6x6a21x5757xff0cx6dfbx52a0x5f20x8f89x90aex7bb1xff0cx589ex52a0x7535x8bddx53f7x7801x8f93x5165x9650x5236xff0cx4feex6b63TEXTx987ax5e8fx9519x8befxff0cx6dfbx52a0IP138x5ef6x8fdf
ProductName: x95eex9898x53cdx9988
ProductVersion: 1.01.0006
OriginalFilename: x5728x7ebfx62a5x4fee.exe

NewHeur_VB_Downloader.3 also known as:

DrWebTrojan.DownLoader32.51971
MicroWorld-eScanGen:Trojan.Heur.VP.cm0@aWleUCkb
FireEyeGen:Trojan.Heur.VP.cm0@aWleUCkb
CAT-QuickHealTrojandownloader.Generic
Qihoo-360Generic/Trojan.2ca
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Trojan.Heur.VP.cm0@aWleUCkb
K7GWTrojan ( 0050df7f1 )
K7AntiVirusTrojan ( 0050df7f1 )
BitDefenderThetaAI:Packer.A3449F901F
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
GDataGen:Trojan.Heur.VP.cm0@aWleUCkb
KasperskyHEUR:Trojan-Downloader.Win32.Generic
AlibabaTrojanDownloader:Win32/NewHeur.1a9e61f7
NANO-AntivirusTrojan.Win32.Razy.gwfsre
AegisLabTrojan.Win32.Generic.a!c
AvastWin32:Trojan-gen
RisingDownloader.Generic!8.141 (CLOUD)
Ad-AwareGen:Trojan.Heur.VP.cm0@aWleUCkb
SophosMal/Generic-S
ComodoMalware@#3ejqz7cp0yi2f
F-SecureTrojan.TR/Dldr.Agent.dpmsk
ZillyaDownloader.Generic.Win32.9510
TrendMicroTROJ_GEN.R011C0PAR20
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftGen:Trojan.Heur.VP.cm0@aWleUCkb (B)
IkarusTrojan.NewHeur_VB_Downloader
CyrenW32/Trojan.XUAV-7963
JiangminTrojanDownloader.Generic.bffd
AviraTR/Dldr.Agent.dpmsk
Endgamemalicious (high confidence)
ArcabitTrojan.Heur.VP.ED1CF6
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
MAXmalware (ai score=99)
ESET-NOD32a variant of NewHeur_VB_Downloader.3
TrendMicro-HouseCallTROJ_GEN.R011C0PAR20
TencentWin32.Trojan.Heur.Wlzd
eGambitUnsafe.AI_Score_87%
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
Cybereasonmalicious.4c5dda
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.7175239.susgen

How to remove NewHeur_VB_Downloader.3?

NewHeur_VB_Downloader.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment