Trojan

Win32/TrojanDownloader.VB.PNM malicious file

Malware Removal

The Win32/TrojanDownloader.VB.PNM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.VB.PNM virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.VB.PNM?


File Info:

name: BD09F56CD2A7B5DD8915.mlw
path: /opt/CAPEv2/storage/binaries/4f5b95f4365e0847a79bd549899d567b66c106be2f10fe58eb93d8f78548eee3
crc32: 7ACD1A9B
md5: bd09f56cd2a7b5dd891585a3c37ad5da
sha1: 022b2a795af93873399beed0a018611ddb57f3b1
sha256: 4f5b95f4365e0847a79bd549899d567b66c106be2f10fe58eb93d8f78548eee3
sha512: 748b9a835d25c1b9bf34d24d69f48ab0f3a83356fd4d8289492681edd24e4a3e209a6f5e32463106e90eda449ec5121aee42a3d2621280e9de4410deb3656d55
ssdeep: 192:bd4OpvuiKlo5gW89K84GvCe4OpvuiKlo5JK:+iKlpW8x46QiKlMK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DD20747F22D5AB2C1DB173706ABC42931B334624B7B0A866F28A3365CA1F550E4DB1B
sha3_384: cc85297137a532a06d71e4fefbf6e51e58c931bcd829203d259312a07e40d6a4f22444ddb9d3fa726dd8fef4c613288f
ep_bytes: 60be005040008dbe00c0ffff5783cdff
timestamp: 2012-01-13 16:59:47

Version Info:

0: [No Data]

Win32/TrojanDownloader.VB.PNM also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Mint.Zard.11
FireEyeGeneric.mg.bd09f56cd2a7b5dd
ALYacGen:Heur.Mint.Zard.11
CylanceUnsafe
SangforVISUAL BASIC4
BitDefenderGen:Heur.Mint.Zard.11
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.VB.PNM
APEXMalicious
KasperskyTrojan-Downloader.Win32.Genome.dtjp
RisingDownloader.VB!8.1EB (RDMK:cmRtazrDAh8lojwk2OwZNN1qqz7K)
Ad-AwareGen:Heur.Mint.Zard.11
SophosGeneric ML PUA (PUA)
DrWebTrojan.DownLoader5.49387
ZillyaDownloader.VB.Win32.112248
McAfee-GW-EditionBehavesLike.Win32.Generic.mz
EmsisoftGen:Heur.Mint.Zard.11 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Zard.11
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C28148
Acronissuspicious
McAfeeRDN/Generic Downloader.x
YandexTrojan.DL.VB!aGTu9P9TV9k
IkarusTrojan-Downloader.Win32.Genome
MaxSecureTrojan.Malware.7164915.susgen
BitDefenderThetaAI:Packer.9A1D2D051D
AVGFileRepMalware [Misc]
Cybereasonmalicious.cd2a7b
AvastFileRepMalware [Misc]

How to remove Win32/TrojanDownloader.VB.PNM?

Win32/TrojanDownloader.VB.PNM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment