Trojan

About “TrojanDownloader:Win32/VB.ZJ” infection

Malware Removal

The TrojanDownloader:Win32/VB.ZJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/VB.ZJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/VB.ZJ?


File Info:

name: 3D5AE23774A15E1E19DB.mlw
path: /opt/CAPEv2/storage/binaries/fe0e8d754858eebd5c4928de7fa95260addab8ea481cb7258e47477a7eae63d2
crc32: 6E7E5AEC
md5: 3d5ae23774a15e1e19dbddb184540277
sha1: 71f855bde22af69c313a00b2c5424b6e3d2d6301
sha256: fe0e8d754858eebd5c4928de7fa95260addab8ea481cb7258e47477a7eae63d2
sha512: 55786e15bb5fd280c03811c09fa2d72eaad9c1869a8da2277a456be95932bd50cf59fca4d894c917da0acea1d56b870921053868e16ceb3868e61cd645c28fb8
ssdeep: 1536:2X9ady/oE2zcEooayWxqKRZoQNkIM71Ni:2X9adywpcEooayWxqRSMpNi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124635DA2A6955C43E0C77FB51B8389F54973A54A0B133256F28C672EAD39F301829FD3
sha3_384: 92df13104fb2bd8883b1808c10c197f10bb3d2c48de96f36e4197c48f56e3c08d8db072c86330e0719ed73daf0db10b0
ep_bytes: 68f4124000e8eeffffff000040000000
timestamp: 2009-03-27 05:33:13

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Me Productions
ProductName: Config
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename: .ocx

TrojanDownloader:Win32/VB.ZJ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scar.4!c
AVGWin32:Trojan-gen
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader8.6222
MicroWorld-eScanGen:Variant.Tedy.151651
FireEyeGeneric.mg.3d5ae23774a15e1e
SkyhighBehavesLike.Win32.VBObfus.km
McAfeeArtemis!3D5AE23774A1
Cylanceunsafe
ZillyaTrojan.Scar.Win32.41779
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojanDownloader:Win32/Injector.dd8c0257
K7GWTrojan ( 0055e3991 )
BitDefenderThetaAI:Packer.49F84D6E20
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.AJL
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Scar.dhlw
BitDefenderGen:Variant.Tedy.151651
NANO-AntivirusTrojan.Win32.Scar.cpmqo
TencentWin32.Trojan.Scar.Bgow
EmsisoftGen:Variant.Tedy.151651 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Tedy.151651
SophosML/PE-A
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Scar
KingsoftWin32.Trojan.Scar.dhlw
MicrosoftTrojanDownloader:Win32/VB.ZJ
XcitiumTrojWare.Win32.TrojanDownloader.VB.~YA@ajtjy
ArcabitTrojan.Tedy.D25063
ZoneAlarmTrojan.Win32.Scar.dhlw
GDataGen:Variant.Tedy.151651
GoogleDetected
AhnLab-V3Trojan/Win32.Xema.C133578
VBA32Trojan.VBRA.04639
ALYacGen:Variant.Tedy.151651
PandaTrj/CI.A
RisingMalware.Undefined!8.C (TFE:3:NpqmAJ1pi7O)
YandexTrojan.GenAsa!rgsk79xw5CY
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.1854037.susgen
FortinetW32/Scar.DHLW!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Scar.dhlw

How to remove TrojanDownloader:Win32/VB.ZJ?

TrojanDownloader:Win32/VB.ZJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment