Trojan

Win32/TrojanDownloader.VB.RIR removal instruction

Malware Removal

The Win32/TrojanDownloader.VB.RIR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.VB.RIR virus can do?

  • Executable code extraction
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Generates some ICMP traffic
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/TrojanDownloader.VB.RIR?


File Info:

crc32: E1364AAD
md5: 9f74df24690e764f655e99f7cb3403bf
name: 9F74DF24690E764F655E99F7CB3403BF.mlw
sha1: f3cbd4ae654b7f1f15617131ecb5ce9aa38b061d
sha256: c889542a87b36c0465db6786d12b735255f0fd7d63bf1452760c9545ecd9b812
sha512: 947c855917d8ffccc56dec3a60746986e8b8f779ed3cc7f63e6c1616ab09862a9b95918fadde9def09ddbf9c10a3a4b2966154d6e82965ed571f9685662d4c98
ssdeep: 192:bpbpEzmlLwNyvyq/vCViw15u28JiK/ta+reI:bhWqwkF/vCViw7u28J3laceI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: Project1
FileVersion: 1.00
OriginalFilename: Project1.exe
ProductName: Project1

Win32/TrojanDownloader.VB.RIR also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan-Downloader ( 0054851e1 )
DrWebTrojan.Siggen8.13833
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31743768
AlibabaTrojanDownloader:Win32/Alien.130f13d5
K7GWTrojan-Downloader ( 0054851e1 )
Cybereasonmalicious.4690e7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.VB.RIR
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.31743768
NANO-AntivirusTrojan.Win32.Alien.fnvpxb
MicroWorld-eScanTrojan.GenericKD.31743768
TencentWin32.Trojan.Alien.Hwwi
Ad-AwareTrojan.GenericKD.31743768
SophosMal/Generic-S
ComodoMalware@#1jc9rxm2qv43k
BitDefenderThetaGen:NN.ZevbaF.34170.bm0@a8yrF!fi
McAfee-GW-EditionBehavesLike.Win32.Trojan.mz
FireEyeGeneric.mg.9f74df24690e764f
EmsisoftTrojan.GenericKD.31743768 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Alien.ci
AviraHEUR/AGEN.1138254
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.2AC18A5
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D1E45F18
GDataWin32.Trojan.Agent.ALJ
AhnLab-V3Trojan/Win32.Agent.C3122853
McAfeeArtemis!9F74DF24690E
MAXmalware (ai score=84)
VBA32BScope.TrojanDownloader.Bitmin
YandexTrojan.GenAsa!LOiQpYSV0A0
IkarusTrojan-Downloader.Win32.VB
FortinetW32/VB.RIR!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/TrojanDownloader.VB.RIR?

Win32/TrojanDownloader.VB.RIR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment