Trojan

Trojan:Win32/VB.AHR removal

Malware Removal

The Trojan:Win32/VB.AHR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VB.AHR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

7k5butq58.co.cc
ocsp.comodoca.com
crl.usertrust.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Trojan:Win32/VB.AHR?


File Info:

crc32: D1435A58
md5: 5d6ec9dd08fcda47fa67b43f4694e518
name: 5D6EC9DD08FCDA47FA67B43F4694E518.mlw
sha1: f27b72cd9556cc59617a425f2bc12d8f0e4e1a26
sha256: dcd9c0612d9b36d21ed48b04e55e4a542211811d1412a9588e46c642ac20349e
sha512: 7381482c78cac60dc29c24b8f41067456a1f327ae91c4169e95db3faee9cfef18cd5fbcc271a07d9982eba3e78513365889995eb89bc7dc37ed85a41809d3ce0
ssdeep: 384:/TihHK1GvhRDKe6vB0iKZ5qNjKRGsFp/R3JLouuGp6RazaUj+KY9qIQq9H9mmPAp:/WVKIhR2eRi88STR35zzaU7byh3ryI9s
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: rqtabxmhmvwqn
FileVersion: 1.00
OriginalFilename: rqtabxmhmvwqn.exe
ProductName: eyqgrjsupgm

Trojan:Win32/VB.AHR also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.85242
FireEyeGeneric.mg.5d6ec9dd08fcda47
ALYacGen:Variant.Johnnie.85242
CylanceUnsafe
VIPRELooksLike.Win32.Malware!vb (v)
SangforMalware
BitDefenderGen:Variant.Johnnie.85242
Cybereasonmalicious.d08fcd
BitDefenderThetaGen:NN.ZevbaF.34804.cm1@a8vCTMni
CyrenW32/VB.EA.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/VBDownloader.B!generic
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ragterneb.afx
NANO-AntivirusTrojan.Win32.VB.iktli
ViRobotTrojan.Win32.A.Ragterneb.32768.E
TencentWin32.Trojan.Ragterneb.Sxys
Ad-AwareGen:Variant.Johnnie.85242
SophosMal/Generic-R + Mal/VBCheMan-F
ComodoTrojWare.Win32.TrojanDownloader.VB.PLV@4oyf3x
F-SecureTrojan.TR/VB.Agent.ahrna
DrWebTrojan.Siggen3.44520
ZillyaDownloader.VB.Win32.79374
McAfee-GW-EditionBehavesLike.Win32.Trojan.nt
EmsisoftGen:Variant.Johnnie.85242 (B)
SentinelOneStatic AI – Malicious PE – Downloader
WebrootW32.Malware.Gen
AviraTR/VB.Agent.ahrna
Antiy-AVLTrojan/Win32.Ragterneb
KingsoftWin32.Troj.Ragterneb.a.(kcloud)
MicrosoftTrojan:Win32/VB.AHR
ArcabitTrojan.Johnnie.D14CFA
SUPERAntiSpywareTrojan.Agent/Gen-Faker[internal]
ZoneAlarmTrojan.Win32.Ragterneb.afx
GDataGen:Variant.Johnnie.85242
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.ADH.C133891
McAfeeArtemis!5D6EC9DD08FC
MAXmalware (ai score=87)
VBA32Trojan.Ragterneb
MalwarebytesMalware.AI.3825920126
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.VB.PLV
TrendMicro-HouseCallTROJ_VBDLOADER_0000004.TOMA
RisingDownloader.VB!8.1EB (TFE:5:4qkAu86fPWK)
YandexTrojan.GenAsa!qZOJyxh5CiI
IkarusTrojan.VB
eGambitUnsafe.AI_Score_92%
FortinetW32/VBCheMan.A
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Downloader.93c

How to remove Trojan:Win32/VB.AHR?

Trojan:Win32/VB.AHR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment