Malware

Should I remove “VHO:AdWare.Win32.Burden”?

Malware Removal

The VHO:AdWare.Win32.Burden is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:AdWare.Win32.Burden virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Collects information about installed applications

How to determine VHO:AdWare.Win32.Burden?


File Info:

crc32: 37D6F77E
md5: 651f629c4f903f63b7c8fcd8aab2b23c
name: 651F629C4F903F63B7C8FCD8AAB2B23C.mlw
sha1: f8d6a6764b985e87c6168bbc53122b0b6f13a494
sha256: 204aff4913a79ee12c67b0de31de5b797c996862c812e8f9db563cdf930c8acf
sha512: 11305c5f30badd7d74f41c00b7917d7485b26a5721eac7c812feb85c2a6c93c9acff0fcd0b87bfa2d48e2fb5c56ba1f2bdaf113641b4d346aae4dfd66ee070af
ssdeep: 49152:p+dzKs445EK/yeb1YOPSkCq7NCcPfkES1+m7l/I:p+dzKsZEK/3b1YXq7NCQf
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2021
InternalName: x4e07x80fdx6062x590dx5927x5e08
CompanyName: x4e0ax6d77x4e1cx65b9x7f51x80a1x4efdx6709x9650x516cx53f8
ProductName: x4e07x80fdx6062x590dx5927x5e08
ProductVersion: 1,0,4,21610
FileDescription: x4e07x80fdx6062x590dx5927x5e08
OriginalFilename: WRSvcmbdl.dll
Translation: 0x0804 0x04b0

VHO:AdWare.Win32.Burden also known as:

Elasticmalicious (high confidence)
DrWebAdware.Softcnapp.165
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaAdWare:Win32/Softcnapp.2ce17b38
K7GWAdware ( 00575b891 )
K7AntiVirusAdware ( 00575b891 )
SymantecRansom.Wannacry
ESET-NOD32a variant of Win32/Softcnapp.BH potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:VHO:AdWare.Win32.Burden.gen
SophosSoftcnapp (PUA)
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.651f629c4f903f63
SentinelOneStatic AI – Suspicious PE
Antiy-AVLTrojan/Generic.ASMalwS.3332C51
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftAdware.Softcnapp.vl!c
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Burden.gen
GDataWin32.Application.Agent.PLLV5N
McAfeeArtemis!651F629C4F90
MalwarebytesPUP.Optional.ChinAd
PandaTrj/Genetic.gen
RisingAdware.Agent!1.C6F0 (CLASSIC)
IkarusPUA.Softcnapp
MaxSecureAdware.notavirus.WIN32.AdWare.Burden.gen_211828
FortinetRiskware/Softcnapp
AVGWin32:Adware-gen [Adw]

How to remove VHO:AdWare.Win32.Burden?

VHO:AdWare.Win32.Burden removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment