Backdoor

VHO:Backdoor.Win32.Carbanak removal

Malware Removal

The VHO:Backdoor.Win32.Carbanak is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Backdoor.Win32.Carbanak virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VHO:Backdoor.Win32.Carbanak?


File Info:

name: 0E580B07E3CAFD59A41A.mlw
path: /opt/CAPEv2/storage/binaries/16c476fdf28575b537f2bc55edcb37eccea921a17fff07960c95702bd340a137
crc32: CD0EA793
md5: 0e580b07e3cafd59a41abb2fba3a6795
sha1: 56237d97e2216e3295131260bf151ded1b5fca77
sha256: 16c476fdf28575b537f2bc55edcb37eccea921a17fff07960c95702bd340a137
sha512: 46df6fb606e18aaade8c46b4ed8719fee4f1efcc8e96e29c9a64b16e21f3b82090167365902022acdffbb8c8331cbbd0dbb81283fdafe00a81caf20ba4729b07
ssdeep: 24576:ZhOa+9EuP9HxoXZoVeCe6TXjJpsB8jIy:TOaexTz7sU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A405B063DAA191F9C867C0B0926B2739FB31749141387F8E97D82F521F27614B32E399
sha3_384: 29af8c62d3747af875329d136fa1b679a6ac536ac69f9e86a6f99f41aa4ad32244dbc54485ee37d229bfcc39040f766b
ep_bytes: 5756536816104000e8230000005b5e5f
timestamp: 2018-08-09 09:29:31

Version Info:

0: [No Data]

VHO:Backdoor.Win32.Carbanak also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.0e580b07e3cafd59
McAfeeArtemis!0E580B07E3CA
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWHacktool ( 700007861 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34742.WqZ@aektLPn
ESET-NOD32a variant of Win32/TrojanDownloader.Nymaim.BA
KasperskyVHO:Backdoor.Win32.Carbanak.gen
AvastWin32:Trojan-gen
SophosGeneric ML PUA (PUA)
ZillyaDownloader.Nymaim.Win32.10378
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
SentinelOneStatic AI – Malicious PE
APEXMalicious
AviraHEUR/AGEN.1230583
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Nymaim
RisingTrojan.Generic@AI.100 (RDML:/wyicJaxPF9lQSRuU5Z9Cg)
IkarusVirus.Win32.Xpaj
AVGWin32:Trojan-gen
Cybereasonmalicious.7e2216

How to remove VHO:Backdoor.Win32.Carbanak?

VHO:Backdoor.Win32.Carbanak removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment