Trojan

Should I remove “Trojan.Sunburst.B (B)”?

Malware Removal

The Trojan.Sunburst.B (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Sunburst.B (B) virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content

How to determine Trojan.Sunburst.B (B)?


File Info:

name: 3E329A4C9030B26BA152.mlw
path: /opt/CAPEv2/storage/binaries/d3c6785e18fba3749fb785bc313cf8346182f532c59172b69adfb31b96a5d0af
crc32: EE829C13
md5: 3e329a4c9030b26ba152fb602a1d5893
sha1: ebe711516d0f5cd8126f4d53e375c90b7b95e8f2
sha256: d3c6785e18fba3749fb785bc313cf8346182f532c59172b69adfb31b96a5d0af
sha512: 95f0308b8b9c1263c3318e4577446572190e508c9fbb87f3170dd1bfe104e01bfcb97537648eca4ef123e3f15d79b53ea702553a7433dbaf3d543b045d2ecb3e
ssdeep: 24576:ddBfeHcrhCECR1R/zoi8SHoN0W8vB8O3IcH:Re8nK/zopSHoN0W8vB8m
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DB15C40173EC8609F5FB2B787AB041190B73B9669976D70E198C649E0FB3B408E51BB7
sha3_384: 4addd5182d51214dc459e61fb92ccf0b2404dd483aff3ad9cff5d6d8390112cdddad4c2d58529c0002f9d41d499d76b0
ep_bytes: ff250020001001000000020000000300
timestamp: 2019-10-10 13:26:39

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: SolarWinds Worldwide, LLC.
FileDescription: SolarWinds.Orion.Core.BusinessLayer
FileVersion: 2019.4.5200.8890
InternalName: SolarWinds.Orion.Core.BusinessLayer.dll
LegalCopyright: Copyright © 1999-2019 SolarWinds Worldwide, LLC. All Rights Reserved.
LegalTrademarks:
OriginalFilename: SolarWinds.Orion.Core.BusinessLayer.dll
ProductName: SolarWinds.Orion.Core.BusinessLayer
ProductVersion: 2019.4.5200.8890
Assembly Version: 2019.4.5200.8890

Trojan.Sunburst.B (B) also known as:

BkavW32.Common.28EFB0D0
DrWebBackDoor.Siggen2.3346
MicroWorld-eScanTrojan.Sunburst.B
SkyhighTrojan-sunburst
McAfeeTrojan-sunburst
MalwarebytesBackdoor.Sunburst
ZillyaBackdoor.Sunburst.Win32.1
SangforTrojan.MSIL.Solarwinds.IOC
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
Elasticmalicious (high confidence)
TrendMicro-HouseCallTROJ_GEN.R002C0DGN23
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Sunburst.B
EmsisoftTrojan.Sunburst.B (B)
F-SecureTrojan:W32/Sunburst.F
VIPRETrojan.Sunburst.B
TrendMicroTROJ_GEN.R002C0DGN23
IkarusBackdoor.Siggen
MAXmalware (ai score=99)
JiangminBackdoor.MSIL.ebbj
WebrootW32.Trojan.Sunburst
GoogleDetected
AviraTR/Redcap.exspb
VaristW32/ABTrojan.CSFL-0204
Antiy-AVLTrojan[APT]/Win32.Unc2452
MicrosoftTrojan:MSIL/Solorigate.BR!dha
XcitiumMalware@#aguwggb5iyn3
ArcabitTrojan.Sunburst.B
ViRobotBackdoor.Win32.S.sunburst.940304
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Backdoor/Win.SunBurst.R456620
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacTrojan.MSIL.SunBurst
Cylanceunsafe
PandaTrj/Solorigate.A
MaxSecureTrojan.Malware.111377877.susgen
FortinetW32/Sunburst.A!tr

How to remove Trojan.Sunburst.B (B)?

Trojan.Sunburst.B (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment