Trojan

TrojanDownloader:Win32/VB removal tips

Malware Removal

The TrojanDownloader:Win32/VB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/VB virus can do?

  • Executable code extraction
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:Win32/VB?


File Info:

crc32: 14D07857
md5: 7d39bc4347e01ada4d51867418801084
name: 7D39BC4347E01ADA4D51867418801084.mlw
sha1: a5a1cc8f52850d22953838de242605aaf4a35bf0
sha256: f94ad65450a43d8601ad22422d5a71be8dbaf4e4fdf155ed95dfd8ca234fd0e0
sha512: 04e3c1af71ca26ecf2ccac9c00665ce4a67886cc20fbe2702415e95a5bd1da68ba130a796e4d67bc96d2ade32dab43203271ce67339f0d9cc2c00ea86e0c5025
ssdeep: 1536:8PP16Xh9quucjghNemENTyOu7fMWFmsI2GvqtKmeryXV:8PAXh9ocjghI9I70mI2GiMmLV
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0804 0x04b0
InternalName: x5de5x7a0b1
FileVersion: 5.01.2628
CompanyName: Microsoft Corporation
Comments: x81eax52a8x4e0bx8f7dx5b89x88c5x7cfbx7edf
ProductName: x81eax52a8x4e0bx8f7dx5b89x88c5x7cfbx7edf
ProductVersion: 5.01.2628
FileDescription: x81eax52a8x4e0bx8f7dx5b89x88c5x7cfbx7edf
OriginalFilename: x5de5x7a0b1.exe

TrojanDownloader:Win32/VB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.40595850
FireEyeGeneric.mg.7d39bc4347e01ada
ALYacTrojan.GenericKD.40595850
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.40595850
K7GWTrojan ( 004bcce71 )
K7AntiVirusTrojan ( 004bcce71 )
BaiduWin32.Trojan.VB.hn
SymantecDownloader
TotalDefenseWin32/VB.AL
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.VB-6820
KasperskyTrojan.Win32.VB.fse
AlibabaTrojanDownloader:Win32/Generic.6adef149
NANO-AntivirusTrojan.Win32.VB.pjsl
AegisLabTrojan.Win32.VB.4!c
RisingTrojan.DL.Win32.VB.ywk (CLASSIC)
Ad-AwareTrojan.GenericKD.40595850
EmsisoftTrojan.GenericKD.40595850 (B)
ComodoTrojWare.Win32.Trojan.VB.~W@1es59r
F-SecureTrojan.TR/Crypt.FKM.Gen
DrWebTrojan.Siggen3.25235
ZillyaTrojan.Katusha.Win32.15537
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
MaxSecureTrojan.Malware.794254.susgen
CMCGeneric.Win32.7d39bc4347!CMCRadar
SophosML/PE-A + Mal/VB-G
IkarusTrojan.Win32.VB
JiangminTrojan/VB.czey
WebrootW32.Malware.Downloader
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Win32.VB
MicrosoftTrojanDownloader:Win32/VB
ArcabitTrojan.Generic.D26B718A
ZoneAlarmTrojan.Win32.VB.fse
GDataTrojan.GenericKD.40595850
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.VB.C37643
McAfeeGeneric.dx!hv.g
MAXmalware (ai score=100)
VBA32Trojan.VBRA.02582
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.VB.NQS
TencentMalware.Win32.Gencirc.114ccb80
YandexTrojan.VB!H12poqmGRgc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/VB.G
BitDefenderThetaAI:Packer.66343A8620
AVGWin32:Malware-gen
Qihoo-360Trojan.Generic

How to remove TrojanDownloader:Win32/VB?

TrojanDownloader:Win32/VB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment