Trojan

Trojan:Win32/Vorus.DB malicious file

Malware Removal

The Trojan:Win32/Vorus.DB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vorus.DB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Vorus.DB?


File Info:

name: 8A704C8455CF7142B06A.mlw
path: /opt/CAPEv2/storage/binaries/d6c50b12e742bb2050152ea83697a67770df435bf23943a8122f9a3b1087c786
crc32: CADA7848
md5: 8a704c8455cf7142b06ad6fd4a4c9920
sha1: a284fc64f55d52de504961c682d5240b7f18ab78
sha256: d6c50b12e742bb2050152ea83697a67770df435bf23943a8122f9a3b1087c786
sha512: a688f0c46ffb2b9c9d6de5ab664343201acbdbf60d7195e2090bc1351acdf1bc5fdb4b48f6c840991db043310d076118a8887637cf0476b37d4d4c21be5bff0d
ssdeep: 768:aJSwpbhhMwNmF1PQVZsDA1fFYM9M2AT9G4uJ:aJSA0wu18fL22ATpuJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11453B7C2735AC596D49216790B1F53211FE2BCC61B23B602F692BBABE873D0C19F5643
sha3_384: 587bf6effb77f5f55ec6c91f346b87d1f8bbcbd470d49f486497e9eeb5f6bca747882c8f419971d3ec77c087dc3b6689
ep_bytes: 68d0324000e8f0ffffff000040000000
timestamp: 2007-05-20 01:35:17

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Rat nguy hiem khong nen chay
FileDescription: Hailua - Ben Tre
LegalCopyright: 2007
ProductName: Hailua
FileVersion: 1.00
ProductVersion: 1.00
InternalName: hllp
OriginalFilename: hllp.exe

Trojan:Win32/Vorus.DB also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VB.kZyt
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Siggen.2905
MicroWorld-eScanGen:Variant.Graftor.27488
FireEyeGeneric.mg.8a704c8455cf7142
CAT-QuickHealWorm.VB.CB4
SkyhighW32/YahLover.worm.h
McAfeeW32/YahLover.worm.h
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005640b91 )
K7GWP2PWorm ( 0013273b1 )
Cybereasonmalicious.455cf7
VirITWorm.Win32.VB.AS
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.OCT
ZonerTrojan.Win32.34578
APEXMalicious
ClamAVWin.Worm.VB-1038
KasperskyIM-Worm.Win32.VB.as
BitDefenderGen:Variant.Graftor.27488
NANO-AntivirusTrojan.Win32.Dunco.crsvyu
AvastWin32:VB-GNO [Wrm]
TencentWorm.Win32.VB.ahi
EmsisoftGen:Variant.Graftor.27488 (B)
GoogleDetected
BaiduWin32.Worm-IM.VB.a
VIPREGen:Variant.Graftor.27488
Trapminemalicious.high.ml.score
SophosMal/VB-F
SentinelOneStatic AI – Malicious PE
JiangminWorm/VB.raa
VaristW32/S-f5173011!Eldorado
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.VB
Kingsoftmalware.kb.a.979
MicrosoftTrojan:Win32/Vorus.DB
XcitiumIMWorm.Win32.VB.~SAA@65lnb
ArcabitTrojan.Graftor.D6B60
ViRobotWorm.Win32.IM-VB.61524
ZoneAlarmIM-Worm.Win32.VB.as
GDataGen:Variant.Graftor.27488
AhnLab-V3Worm/Win32.AutoRun.R42596
ALYacGen:Variant.Graftor.27488
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Adbrite.T.worm
TrendMicro-HouseCallWORM_VB.EDD
RisingWorm.DungCoi!1.CE99 (CLASSIC)
YandexTrojan.GenAsa!DRNug6UMc90
IkarusIM-Worm.Win32.VB
FortinetW32/VB.NZK!tr
AVGWin32:VB-GNO [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm[im]:Win/Vorus.DB

How to remove Trojan:Win32/Vorus.DB?

Trojan:Win32/Vorus.DB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment