Trojan

Trojan:Win32/VB.AHV removal tips

Malware Removal

The Trojan:Win32/VB.AHV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VB.AHV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to disable UAC
  • The sample wrote data to the system hosts file.
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/VB.AHV?


File Info:

name: ECB292FF0547FC44A098.mlw
path: /opt/CAPEv2/storage/binaries/33aa56d6ae850e551f45e4f5d2db217935c807f4d5bcda78d4d651210e6525ca
crc32: 13CD919A
md5: ecb292ff0547fc44a0984ea0a8e32b59
sha1: 1ec8bfdb056e1fdb36acd83db765565aa75123b0
sha256: 33aa56d6ae850e551f45e4f5d2db217935c807f4d5bcda78d4d651210e6525ca
sha512: a5830c065468e8782b8a0444569df98cb21dd51b893af76d2163ac3cea840943ff1493727adcfc7b33f9f4f52a25c69c07ba881d25bd3fea5c5390884d6e70fb
ssdeep: 384:XdFKhMjstW2OlSvdgf0ScYrm8HAD0I6baD3W4qhzEc:qOHpv1VgD0Iag7t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EE2B63BE408653AF788C1B34A7581AB745A3D329550DE07768A7F5E2D31593B8E070F
sha3_384: 838f08a2e1434fb307c91040c5090956a69925678882dd78dc4cbcde9b4314c42721ffd89a643888460dfae486ecddff
ep_bytes: 68f4174000e8f0ffffff000000000000
timestamp: 2011-11-14 15:44:59

Version Info:

Translation: 0x0c0a 0x04b0
CompanyName: D3xt3r
ProductName: Proyecto1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Proyecto1
OriginalFilename: Proyecto1.exe

Trojan:Win32/VB.AHV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.4!c
MicroWorld-eScanGen:Variant.Doina.38262
FireEyeGeneric.mg.ecb292ff0547fc44
SkyhighBehavesLike.Win32.Generic.nz
ALYacGen:Variant.Doina.38262
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Doina.38262
SangforTrojan.Win32.Qhost.OOY
BitDefenderGen:Variant.Doina.38262
Cybereasonmalicious.b056e1
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Qhost.OOY
APEXMalicious
ClamAVWin.Ransomware.Qhost-7672209-0
KasperskyTrojan.Win32.VB.cgbb
AlibabaTrojan:Win32/Qhost.db56f7e1
NANO-AntivirusTrojan.Win32.VB.qovvz
RisingTrojan.Qhost!8.1B0 (TFE:5:WCMuZq8i5Q)
SophosMal/VB-ABO
F-SecureTrojan.TR/VB.Downloader.Gen
ZillyaTrojan.Qhost.Win32.10074
EmsisoftGen:Variant.Doina.38262 (B)
MAXmalware (ai score=100)
JiangminTrojan.VB.ypy
GoogleDetected
AviraTR/VB.Downloader.Gen
Antiy-AVLTrojan/Win32.VB
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojan:Win32/VB.AHV
XcitiumMalware@#q685nxvera22
ArcabitTrojan.Doina.D9576
ZoneAlarmTrojan.Win32.VB.cgbb
GDataGen:Variant.Doina.38262
CynetMalicious (score: 99)
McAfeeArtemis!ECB292FF0547
DeepInstinctMALICIOUS
VBA32Trojan.VB
Cylanceunsafe
PandaGeneric Malware
TencentWin32.Trojan.Vb.Bdhl
YandexTrojan.GenAsa!wewjNp3RECs
IkarusTrojan.Win32.Cossta
MaxSecureTrojan.Malware.74797760.susgen
FortinetW32/VB.VS
BitDefenderThetaGen:NN.ZevbaF.36792.cm0@ayNNDPS
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/VB.AHV?

Trojan:Win32/VB.AHV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment