Trojan

Trojan.Downloader.VB.WHU (file analysis)

Malware Removal

The Trojan.Downloader.VB.WHU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.VB.WHU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Downloader.VB.WHU?


File Info:

name: 294B280708D5FE53ACDF.mlw
path: /opt/CAPEv2/storage/binaries/6f975bccfb0513dcc702be4e6e5977c2cd1fc4879d6f89fa2731182e3739bd39
crc32: 56F63D44
md5: 294b280708d5fe53acdf7899e33a38a6
sha1: c906e73493e38bda6733dcf11bcf404836e99a4f
sha256: 6f975bccfb0513dcc702be4e6e5977c2cd1fc4879d6f89fa2731182e3739bd39
sha512: b067935b17a286336cdf70b37569cc737a7adab83b8b33f28c1d759eee34ec6a96689a4fa68adb6bb53a2b96d5c1075df19763def09c12d6d9c5f21618857cf1
ssdeep: 192:xKat9RewlgYKC+i4J4ZZ7Z/WZDwGRDsIU:pzIw9F+lORIRDsv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A926323642C5672E10C83728A2387F69D27BC306B525D2B39D9EF1E3D347523DD9A0A
sha3_384: 472bf1cbc2592a04f2988185222e50c885032f3e3c12600404659e34ab60ca3ff519766952c7a1aec592871e358dd449
ep_bytes: 6820184000e8eeffffff000000000000
timestamp: 2009-08-21 16:24:24

Version Info:

CompanyName: 叶
ProductName: 工程1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Setup
OriginalFilename: Setup.exe
Translation: 0x0804 0x0400

Trojan.Downloader.VB.WHU also known as:

BkavW32.Common.8DA75D4D
LionicTrojan.Win32.Gendal.4!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Infected.mz
ALYacTrojan.Downloader.VB.WHU
Cylanceunsafe
ZillyaTrojan.Genome.Win32.199627
SangforDownloader.Win32.Agent.V6fe
AlibabaTrojan:Application/Gendal.44abca5e
CrowdStrikewin/malicious_confidence_70% (D)
VirITTrojan.Win32.Generic.CLLY
SymantecTrojan.Gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Generik.GWYJHFM
BitDefenderTrojan.Downloader.VB.WHU
NANO-AntivirusTrojan.Win32.Gendal.drkksl
ViRobotBackdoor.Win32.Shark.20480.C
MicroWorld-eScanTrojan.Downloader.VB.WHU
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.115a2119
TACHYONTrojan/W32.VB-Agent.20480.QK
EmsisoftTrojan.Downloader.VB.WHU (B)
VIPRETrojan.Downloader.VB.WHU
TrendMicroTROJ_GEN.R002C0OAP24
FireEyeGeneric.mg.294b280708d5fe53
SophosMal/Generic-R
JiangminTrojanDownloader.Agent.favn
WebrootW32.Trojan.Trojan-Downloader.Ge
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Downloader.VB.WHU
GDataTrojan.Downloader.VB.WHU
GoogleDetected
McAfeeGenericRXAA-AA!294B280708D5
MAXmalware (ai score=98)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OAP24
RisingTrojan.DL.Win32.VBcode.adq (CLASSIC)
YandexTrojan.DL.VB!3RCOBXh2MQg
IkarusTrojan.Gendal
MaxSecureTrojan.Malware.1284855.susgen
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan.Downloader.VB.WHU?

Trojan.Downloader.VB.WHU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment