Backdoor

VHO:Backdoor.Win32.Brabot information

Malware Removal

The VHO:Backdoor.Win32.Brabot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Backdoor.Win32.Brabot virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine VHO:Backdoor.Win32.Brabot?


File Info:

name: 1056A85F80B5725DAB5B.mlw
path: /opt/CAPEv2/storage/binaries/12e7f55e867e6f80388f8e542c0e48dd68031ff1f099ac95d85ea6d2e3fa5180
crc32: 85193A00
md5: 1056a85f80b5725dab5b61933d993af8
sha1: 90fa256ea09548b7463363970c465713dc873ae4
sha256: 12e7f55e867e6f80388f8e542c0e48dd68031ff1f099ac95d85ea6d2e3fa5180
sha512: 71669323932f8fa9f07a51dd16e89b5e44a91b2fd6018fec9ca189d1605e8c658b8d5ac0f1cb04952b235af87cef64871928fbf85470d32638a4c037ea790bc8
ssdeep: 49152:XtjItUEVP+DGf4aphmlp6OXPkvL830ZMoOd/CZjamwVnz1R151:XCtpWaphmlAuPFhdR51
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T161162890FDDB44B5DA0759304467A27F27306D094F38DBC7EA20BF6AE9736A10E32649
sha3_384: fe8f895f4bae412d4658975f87e57ef4a0d9f81ef28f5085d2362db51e5220cdb2b8424d0033153a61892bb52b1356d9
ep_bytes: e91bddffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

VHO:Backdoor.Win32.Brabot also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
McAfeeArtemis!1056A85F80B5
Cylanceunsafe
CrowdStrikewin/malicious_confidence_70% (W)
KasperskyVHO:Backdoor.Win32.Brabot.gen
McAfee-GW-EditionBehavesLike.Win32.Trojan.wh
WebrootW32.Trojan.Gen
ZoneAlarmVHO:Backdoor.Win32.Brabot.gen
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:kcQv3TNKS1WiL8Bij7VlnQ)
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove VHO:Backdoor.Win32.Brabot?

VHO:Backdoor.Win32.Brabot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment