Malware

What is “Win32/VB.RHM”?

Malware Removal

The Win32/VB.RHM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.RHM virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/VB.RHM?


File Info:

name: 3F929117FCCFC3653B83.mlw
path: /opt/CAPEv2/storage/binaries/6ebad36a4daf8c250cac2f101d8f997aba2ea70121182582a2742d948d6d5f3a
crc32: 66E7D4DA
md5: 3f929117fccfc3653b83cf34182cfcd2
sha1: f5e45d32b77d6e9723949a6253610bb0fc316f20
sha256: 6ebad36a4daf8c250cac2f101d8f997aba2ea70121182582a2742d948d6d5f3a
sha512: a733643a42b84a85f048bcf27c71ad88dbdf4b3fc507954a852f82c05beee5c387806ca353727012ce1d99defd008eca1d8bff9084f36222f1a87886dde47615
ssdeep: 192:pvxROb2cx739u6Z8YYwzCc/pMfsTfehJifLQhChkYhXEHZT1VwTD/Sc5UWjD:pvxRuI1YYqRPfL5kQ42/SgUWj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E2D283636A1E003AEE9CC6F1096786A92D227E311690AD6B759D7E1C1D31B037DF071F
sha3_384: 154168737f416a9648f943d734f91e400b5affdf6823b5ec8f8551d965ac6c5ee9d1b4806a4fde08a3725bca36ca02fe
ep_bytes: 68581b4000e8eeffffff000000000000
timestamp: 2008-11-14 11:35:52

Version Info:

Translation: 0x0804 0x04b0
CompanyName: Microsoft Corporation
ProductName: fas
FileVersion: 1.00
ProductVersion: 1.00
InternalName: nasm
OriginalFilename: nasm.exe

Win32/VB.RHM also known as:

MicroWorld-eScanGen:Trojan.Heur.bm0@s5hCc5fby
FireEyeGen:Trojan.Heur.bm0@s5hCc5fby
ALYacGen:Trojan.Heur.bm0@s5hCc5fby
CylanceUnsafe
VIPREGen:Trojan.Heur.bm0@s5hCc5fby
SangforVISUAL BASIC4
K7AntiVirusP2PWorm ( 004957171 )
AlibabaTrojan:Win32/Generic.221eb6a9
K7GWP2PWorm ( 004957171 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.C4DB530B1D
VirITTrojan.Win32.Generic.YIY
CyrenW32/VB.WP.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VB.RHM
TrendMicro-HouseCallTROJ_GEN.R002H0CGS22
Paloaltogeneric.ml
BitDefenderGen:Trojan.Heur.bm0@s5hCc5fby
NANO-AntivirusTrojan.Win32.Zapchast.jpesph
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Trojan.Heur.bm0@s5hCc5fby
TACHYONTrojan/W32.Zapchast.28672
EmsisoftGen:Trojan.Heur.bm0@s5hCc5fby (B)
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
F-SecureTrojan.TR/Crypt.CFI.Gen
McAfee-GW-EditionBehavesLike.Win32.Trojan.mz
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
GDataGen:Trojan.Heur.bm0@s5hCc5fby
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan/Win32.VB
ArcabitTrojan.Heur.E8E2A4
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.RL_Genome.R367625
McAfeeRDN/Generic.dx
MAXmalware (ai score=86)
MalwarebytesMalware.AI.1386207748
RisingTrojan.Win32.VBCode.en (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.7fccfc

How to remove Win32/VB.RHM?

Win32/VB.RHM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment