Trojan

About “Dropped:Trojan.Vools.A” infection

Malware Removal

The Dropped:Trojan.Vools.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Vools.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Anomalous file deletion behavior detected (10+)
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:63257
  • Enumerates running processes
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Drops a binary and executes it
  • Executes the printer spooler process
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Trojan.Vools.A?


File Info:

name: 7D3CF6BCE43A115399F0.mlw
path: /opt/CAPEv2/storage/binaries/bff25d4a3f3af54689b5603cb3aef84b65b54d62beac64da97b3526d2a4d192a
crc32: ECD7DC14
md5: 7d3cf6bce43a115399f0daaa4b425417
sha1: 611b8bdba97fbf042b3a35277dd641fee753ad01
sha256: bff25d4a3f3af54689b5603cb3aef84b65b54d62beac64da97b3526d2a4d192a
sha512: 9041d54ba3713a4d39952b2932e72c49d9b7e6668d6225b38b4654dff0f87a4a8af2e2860475d06ea440fb1f3c024714bd526035fbc4771de24557b1b4347ec6
ssdeep: 98304:L0UoWf+fO2LGiSdcW+v4fT6gZdDuDSXlu6DXV9coMvwueWNmAVExtO:+WP2LGMhsTfbu+g6rsvwueuX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1033633C975D0D132E2F568320E70EB73AA3CF8749E458D9F731893349F816E96405AAE
sha3_384: 605faaba205d593b487ff24f4eec89bb83e9f15fbc73791e7684681c543b8084fae2822ede9232c1bbd912f9fc43baeb
ep_bytes: e8ad030000e980feffff558bec5156ff
timestamp: 2018-05-03 07:33:47

Version Info:

0: [No Data]

Dropped:Trojan.Vools.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Reconyc.4!c
tehtrisGeneric.Malware
MicroWorld-eScanDropped:Trojan.Vools.A
FireEyeGeneric.mg.7d3cf6bce43a1153
McAfeeGenericRXJJ-EI!7D3CF6BCE43A
CylanceUnsafe
VIPREDropped:Trojan.Vools.A
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005301051 )
AlibabaTrojan:Win32/Miner.652a0613
K7GWTrojan ( 005301051 )
Cybereasonmalicious.ce43a1
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Vools.D
TrendMicro-HouseCallBKDR_VOOLS.C
Paloaltogeneric.ml
ClamAVWin.Tool.Shadowbrokers-9800457-0
KasperskyTrojan.Win32.Miner.uamb
BitDefenderDropped:Trojan.Vools.A
NANO-AntivirusTrojan.Win32.Miner.fbbszp
APEXMalicious
TencentMalware.Win32.Gencirc.10c9833a
Ad-AwareDropped:Trojan.Vools.A
EmsisoftDropped:Trojan.Vools.A (B)
ComodoMalware@#3khln04985nmh
DrWebTrojan.DownLoader26.42972
ZillyaTrojan.Miner.Win32.3724
TrendMicroBKDR_VOOLS.C
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win64.Vools
GDataDropped:Trojan.Vools.A
JiangminTrojan.EquationDrug.ky
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1213479
Antiy-AVLTrojan/Generic.ASMalwS.4E99
KingsoftWin32.Troj.Miner.lc.(kcloud)
ArcabitTrojan.Vools.A
ViRobotTrojan.Win32.Z.Miner.5251584
MicrosoftTrojan:Win32/Occamy.CBF
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2492538
VBA32BScope.Trojan.EquationDrug
ALYacTrojan.Agent.WMAMiner
AvastWin32:Malware-gen
RisingTrojan.Vools/x64!1.B240 (CLASSIC)
YandexTrojan.GenAsa!fHH5uedJPdM
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73379208.susgen
FortinetW32/Vools.D!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Dropped:Trojan.Vools.A?

Dropped:Trojan.Vools.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment