Trojan

Trojan.Win32.VB.dmqp (file analysis)

Malware Removal

The Trojan.Win32.VB.dmqp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VB.dmqp virus can do?

  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Trojan.Win32.VB.dmqp?


File Info:

crc32: 61625C92
md5: 85888ca2f93a78e688be689c0e1a36c0
name: 85888CA2F93A78E688BE689C0E1A36C0.mlw
sha1: 3b169727c3563c006038af1ff1b66e566342500f
sha256: c5196b1788a0a6eb599161242b5a510591803d95753ffb521019785a7f61e01e
sha512: 26f7c9e0f2bd0e1e7011afa30a8491c1f4e7ec58271039facc5a9a71a78aa4a1a3254991f6767683a0774db8be00f42ced78b59e336c05ff2b3c3b78b01a9583
ssdeep: 3072:m/5F/E7tEf0D+p+tYlpJH7iXQNgggHlxDZiYLK5Wpk6outNT/:mhF4cO+wWJH7igNgjdFKsloSV/
type: PE32 executable (Unknown subsystem 0x0) Unknown processor type 0x0 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: DATA
FileVersion: 0.00.0020
CompanyName: Oncom
ProductName: xk
ProductVersion: 0.00.0020
OriginalFilename: DATA.exe

Trojan.Win32.VB.dmqp also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader7.3730
ClamAVWin.Worm.Untukmu-5949608-0
ALYacWorm.Ludbaruma.B
MalwarebytesWorm.AutoRun
ZillyaTrojan.RegrunGen.Win32.1
SangforRansom.Win32.Foreign_11.se
BitDefenderWorm.Ludbaruma.B
K7GWTrojan ( 0040f6141 )
K7AntiVirusTrojan ( 0040f6141 )
BaiduWin32.Worm.VB.k
CyrenW32/Ludbaruma.A.gen!Eldorado
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VB.dmqp
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanWorm.Ludbaruma.B
TencentTrojan-Ransom.Win32.Blocker.kalr
Ad-AwareWorm.Ludbaruma.B
SophosML/PE-A + W32/Mato-N
ComodoTrojWare.Win32.Regrun.Q@1gs3xh
VIPREWorm.Win32.Ludbaruma.a (v)
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.cm
FireEyeWorm.Ludbaruma.B
EmsisoftWorm.Ludbaruma.B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.tav
AviraTR/Agent.gdnw
eGambitUnsafe.AI_Score_100%
MicrosoftWorm:Win32/Bruhorn.B
ArcabitWorm.Ludbaruma.B
GDataWin32.Worm.Ludbaruma.A
TACHYONTrojan/W32.VB-Ludbaruma.Zen
AhnLab-V3Trojan/Win32.Blocker.R233013
Acronissuspicious
McAfeeW32/Rontokbro.gen@MM
MAXmalware (ai score=81)
RisingRansom.Blocker!8.12A (TFE:dGZlOgWKyi/lv9zO9g)
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.VB.dmqp?

Trojan.Win32.VB.dmqp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment