Trojan

Win32/TrojanDownloader.VB.PNG removal instruction

Malware Removal

The Win32/TrojanDownloader.VB.PNG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.VB.PNG virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

dija.franca.sites.uol.com.br
e.indice.uol.com.br
ivetepera.sites.uol.com.br

How to determine Win32/TrojanDownloader.VB.PNG?


File Info:

crc32: FC3FBA1B
md5: 56b648284009fcee9aa3d4215f9987b8
name: 56B648284009FCEE9AA3D4215F9987B8.mlw
sha1: d060e4460d22da72d701ab6a46c6f8c452a926d7
sha256: b02e89c4175acabe11907e6bcd8c57641890df1677265dcc45fc0862a9fbc906
sha512: c2d087b3c068927b745bc3f96005cfa747368ce09c169c9db1367f354534615829262b5f928e181b929287d407cee76935e03639f41054a82000f02715d621f0
ssdeep: 192:Mdk5Ai7rsKBP5ZuOic+Zr63F0HBQchDDsSQtEBdk5Ai7:8et1uOiLqq5DsSQtEDe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Project03
FileVersion: 1.00
CompanyName: BKHN
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: Project03.exe

Win32/TrojanDownloader.VB.PNG also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.35842359
FireEyeGeneric.mg.56b648284009fcee
ALYacTrojan.GenericKD.35842359
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.GenericKD.35842359
K7GWRiskware ( 0015e4f01 )
K7AntiVirusRiskware ( 0015e4f01 )
CyrenW32/VB.CK_b.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Downloader.Win32.Genome.drrm
AlibabaTrojanDownloader:Win32/Genome.c922720a
NANO-AntivirusTrojan.Win32.VB.nfxyd
ViRobotTrojan.Win32.Z.Agent.32768.ICO
AegisLabTrojan.Win32.Generic.a!c
TencentWin32.Trojan-downloader.Genome.Sxes
Ad-AwareTrojan.GenericKD.35842359
EmsisoftTrojan.GenericKD.35842359 (B)
ComodoTrojWare.Win32.TrojanDownloader.VB.PMEA@4rev5s
F-SecureTrojan.TR/VB.Downloader.Gen
DrWebTrojan.DownLoader5.58509
ZillyaDownloader.VB.Win32.36403
TrendMicroTROJ_BANLOD.MJSM
McAfee-GW-EditionBehavesLike.Win32.Trojan.nz
MaxSecureTrojan.Malware.77144952.susgen
SophosMal/Emogen-B
IkarusTrojan-Spy.Zbot
JiangminTrojanDownloader.Genome.aoza
WebrootW32.Malware.Gen
AviraTR/VB.Downloader.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Genome
MicrosoftTrojan:Win32/Orsam!rts
ArcabitTrojan.Generic.D222E937
SUPERAntiSpywareTrojan.Agent/Gen-Banload
ZoneAlarmTrojan-Downloader.Win32.Genome.drrm
GDataWin32.Trojan.VB.TR
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Banker.R65191
McAfeeArtemis!56B648284009
VBA32TrojanDownloader.Genome
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
ESET-NOD32a variant of Win32/TrojanDownloader.VB.PNG
TrendMicro-HouseCallTROJ_BANLOD.MJSM
RisingDownloader.VB!8.1EB (TFE:5:7S0RA7wYEVT)
YandexTrojan.GenAsa!vcFISdvpwkc
eGambitGeneric.Downloader
BitDefenderThetaGen:NN.ZevbaF.34804.cm0@a0htetgi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Downloader.bb3

How to remove Win32/TrojanDownloader.VB.PNG?

Win32/TrojanDownloader.VB.PNG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment