Trojan

Should I remove “VHO:Trojan-Downloader.Win32.Geral”?

Malware Removal

The VHO:Trojan-Downloader.Win32.Geral is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Downloader.Win32.Geral virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

How to determine VHO:Trojan-Downloader.Win32.Geral?


File Info:

name: E33636E3038DD4799958.mlw
path: /opt/CAPEv2/storage/binaries/4cf0c3ce8f90e49ea7424ac60ef75b898c8660a91bdd87bc5c21d55bd34c28ce
crc32: 2FB3E130
md5: e33636e3038dd47999580cfdaf182294
sha1: 71d21baf33952e2aa82204de29e1100ae352c2d5
sha256: 4cf0c3ce8f90e49ea7424ac60ef75b898c8660a91bdd87bc5c21d55bd34c28ce
sha512: 330b3e8e8d0adf512675eb64c710f9c47a989da655f35204ab4c39fd78a8b96f52e701061feab60be74c29c28594ff551aca941a57ebe63edeb8c2bd7aaaea50
ssdeep: 24576:yyivo/oT+mLiGjDA6KuFqGYA0+ztD7vu84CFoVi/LjEmS1jp4GG3:ydv4oRjD5XFgp+zl7u8PFoVWcmS1jp9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E495073370A668E0C43628B45768DAB1ED5CC6AC2B28F98ECB55DC1F7531D86F01AF25
sha3_384: d0ad535761f964ddc0b6bc16812d70e7b86d73b4d54e853389beaceac067882a68f4ef294697b7f3646bec07a5ff1607
ep_bytes: 558bec6aff6878b759006894ab4a0064
timestamp: 2015-08-25 22:10:36

Version Info:

FileVersion: 2.3.0.0
FileDescription: 爱奇艺会员终结者
ProductName: 爱奇艺会员终结者
ProductVersion: 2.3.0.0
CompanyName: bbs.QiYii.cn
LegalCopyright: bbs.QiYii.cn 版权所有
Comments: 爱奇艺会员终结者
Translation: 0x0804 0x04b0

VHO:Trojan-Downloader.Win32.Geral also known as:

LionicTrojan.Win32.Generic.lwoF
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.33501887
FireEyeGeneric.mg.e33636e3038dd479
McAfeeArtemis!E33636E3038D
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Generic.cf76980b
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34606.Zr0@aa!YLykb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
Paloaltogeneric.ml
KasperskyVHO:Trojan-Downloader.Win32.Geral.gen
BitDefenderTrojan.GenericKD.33501887
NANO-AntivirusTrojan.Win32.Agent.dvxzzg
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.33501887
SophosGeneric PUA HB (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
EmsisoftTrojan.GenericKD.33501887 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bigps
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.18BB5A7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C4C
ZoneAlarmVHO:Trojan-Downloader.Win32.Geral.gen
GDataWin32.Trojan.PSE.1CJLVYA
CynetMalicious (score: 100)
VBA32suspected of Trojan.Downloader.gen
ALYacTrojan.GenericKD.33501887
MalwarebytesTrojan.MalPack.FlyStudio
APEXMalicious
RisingTrojan.Generic@AI.89 (RDML:NCnBbe2lHHvF3iCGv7vZ8g)
YandexTrojan.Agent!bOajsPAajSM
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyStudio
AVGWin32:Malware-gen
Cybereasonmalicious.3038dd

How to remove VHO:Trojan-Downloader.Win32.Geral?

VHO:Trojan-Downloader.Win32.Geral removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment