Malware

VHO:Downloader.Win32.Snojan removal guide

Malware Removal

The VHO:Downloader.Win32.Snojan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Downloader.Win32.Snojan virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

Related domains:

2018k.cn

How to determine VHO:Downloader.Win32.Snojan?


File Info:

crc32: E5CA8E60
md5: 06ebe37f799067a68d4f42e5b0e07fac
name: 06EBE37F799067A68D4F42E5B0E07FAC.mlw
sha1: 8e21284cb5e0e1ab89039c61bef8bbd70dcd41fb
sha256: 272c0cf2241992bfd1afe83d344322cbb18d8b80bbe59633d372ef1ff031c0d9
sha512: 4d7835843ab12007dc19f5c27dabaedbb05a3c8e4ff247c3cef5ffed46f75d1a568bf680368301521bfc1aaddf0433025b996df86b224f7af05aa27512c96ff0
ssdeep: 49152:9g8DalkrIc/Sbmo8rCN+Hm1nFaWlYMJJ1othRUIL8G/:9gzlkEc/I18uEHm11S4G/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Qq774429142 x8f6fx4ef6x53eax7528x6765x6d4bx8bd5 x8bf7x52ffx975ex6cd5x4f7fx7528
FileVersion: 1.0.0.0
CompanyName: Qq774429142
Comments: Qq774429142
ProductName: x77edx4fe1x6d4bx538b1.0x7248x672c
ProductVersion: 1.0.0.0
FileDescription: Qq774429142
Translation: 0x0804 0x04b0

VHO:Downloader.Win32.Snojan also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005239691 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWUnwanted-Program ( 004eb1381 )
Cybereasonmalicious.cb5e0e
CyrenW32/S-e743b39f!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.NoobyProtect.F suspicious
APEXMalicious
Kasperskynot-a-virus:VHO:Downloader.Win32.Snojan.gen
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
BitDefenderThetaGen:NN.ZexaF.34692.9v0@aaBmj0gb
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.06ebe37f799067a6
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Heur!.03010021
AegisLabHacktool.Win32.Generic.lvTx
GDataWin32.Packed.NoobyProtect.B
Acronissuspicious
McAfeeGenericRXAA-FA!06EBE37F7990
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrweFfZ33cNtzir4Jm2rm5U)
IkarusPUA.NoobyProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
Paloaltogeneric.ml

How to remove VHO:Downloader.Win32.Snojan?

VHO:Downloader.Win32.Snojan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment