Malware

Mal/Vrom-A (file analysis)

Malware Removal

The Mal/Vrom-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Vrom-A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Slovak
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Mal/Vrom-A?


File Info:

name: 492519304C5C99CDE1F9.mlw
path: /opt/CAPEv2/storage/binaries/92b70dd90ced6016c221d0e07090ebf9145d81c7eabcee0faa7c86e59ab7d4aa
crc32: C694C118
md5: 492519304c5c99cde1f9d0c5586aa5d7
sha1: bca6b32f0c18b7599e6e8f9a9f3e9e00fba9b14f
sha256: 92b70dd90ced6016c221d0e07090ebf9145d81c7eabcee0faa7c86e59ab7d4aa
sha512: 829772e6aa707abde29d180870682e5ba890fc1af6d611798459de25c4f6c15e7c4044901f785eba796f61394c9325a51e70a0ac4e9218b19550e4d3dec6cadb
ssdeep: 3072:y0J0Q/38IF9pTYpt3x6m3yktayFwqS240FD8ywRBvp0pZwzUw:y0Jp8kvTiwGTS2zgBv6fw7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107D312387F56E8AFF2EE21F467D5057518B1CA5297E004830504C39E17FA3852EAEB9E
sha3_384: b06dc134b5940c77b34015d78b8ceb0862b7f20ca68acf9ed8ad6ff30971dcd5eadbf8412a5960a464a1a136bb0c367a
ep_bytes: 60be00f045008dbe0020faff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Mal/Vrom-A also known as:

LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.492519304c5c99cd
McAfeeArtemis!492519304C5C
CylanceUnsafe
Cybereasonmalicious.f0c18b
CyrenW32/Trojan.IZUF-0438
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.2468800-1
ViRobotTrojan.Win32.Generic.142883
AvastFileRepMetagen [Malware]
TencentMalware.Win32.Gencirc.114d85d6
SophosMal/Vrom-A
ComodoMalware@#a4sakom3vzji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.cc
eGambitUnsafe.AI_Score_68%
Antiy-AVLTrojan/Generic.ASMalwS.189CDEB
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Zpevdo.B
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
YandexTrojan.DL.Troxen!OIl1Dvu89Cg
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/Patcher
WebrootW32.Malware.Gen
AVGFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Mal/Vrom-A?

Mal/Vrom-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment