Malware

VHO:Downloader.Win32.VrBrothers removal guide

Malware Removal

The VHO:Downloader.Win32.VrBrothers is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Downloader.Win32.VrBrothers virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine VHO:Downloader.Win32.VrBrothers?


File Info:

name: 0E8692FC9982B0D30639.mlw
path: /opt/CAPEv2/storage/binaries/897b79e2ea420852916f42cf61c4b549860e47d83fdc0da71d57785df2a2757f
crc32: 97C6B41C
md5: 0e8692fc9982b0d3063990f02a84b999
sha1: 873ab6b3e6a8c742ddc90ca206d9101d47366222
sha256: 897b79e2ea420852916f42cf61c4b549860e47d83fdc0da71d57785df2a2757f
sha512: ad46cc3ade4d8e793974a574502ee437470f0426b764da6f2a4105a668e41b73e9a0b9151005182ebea2a143cc1fef86ac975d69202511b65fa8e911123b5446
ssdeep: 24576:0l4UlGZo4PxkGBOAjA29tmf0Zx5DTnQ4RqnXcw1YtoGEcAMzBjBTDscOLrIU/Hg1:0sOFHf0Zxsb1YtoGEcAMzBjBTDjsP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEB56B15EAFBF0A9DD05C03D4DF5EB34AB31EECA5611B6835384FE2C94312A19B250DA
sha3_384: 7c2b7f2c734f501aae58cf9c2f372d113986d97208b12024dac729d5468e443db297ad21fedc09d710482e68a7788d6e
ep_bytes: 558bec6aff6880dd4b00681421420064
timestamp: 2011-04-27 01:51:59

Version Info:

0: [No Data]

VHO:Downloader.Win32.VrBrothers also known as:

BkavW32.AIDetectMalware
DrWebTrojan.KeyLogger.39546
ClamAVWin.Trojan.Agent-6950684-1
CAT-QuickHealPUA.IgenericRI.S28990578
SkyhighBehavesLike.Win32.Dropper.vm
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Patched.Win32.120223
SangforSuspicious.Win32.Save.ins
K7AntiVirusAdware ( 004dc28c1 )
K7GWAdware ( 004dc28c1 )
Cybereasonmalicious.3e6a8c
BitDefenderThetaGen:NN.ZexaF.36792.vsZ@a4mjIfm
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.VrBrothers.AE potentially unwanted
CynetMalicious (score: 100)
Kasperskynot-a-virus:VHO:Downloader.Win32.VrBrothers.gen
NANO-AntivirusTrojan.Win32.KeyLogger.bsksbj
AvastWin32:Malware-gen
F-SecureHeuristic.HEUR/AGEN.1340849
FireEyeGeneric.mg.0e8692fc9982b0d3
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminDownloader.VrBrothers.az
AviraHEUR/AGEN.1340849
Kingsoftmalware.kb.a.986
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmnot-a-virus:VHO:Downloader.Win32.VrBrothers.gen
GDataWin32.Trojan.PSE.IGEZWI
GoogleDetected
McAfeeBot-FGM!0E8692FC9982
VBA32BScope.Trojan.Keyloggerger
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:3D6UI3tSZKmbE/Gv88M2vw)
IkarusTrojan-Dropper.Win32.Small
FortinetAdware/VrBrothers
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove VHO:Downloader.Win32.VrBrothers?

VHO:Downloader.Win32.VrBrothers removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment