Malware

How to remove “Tatrio.4”?

Malware Removal

The Tatrio.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tatrio.4 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

How to determine Tatrio.4?


File Info:

crc32: 9A01E300
md5: d57281cd6901962d2bf4df4e1a4b4d95
name: D57281CD6901962D2BF4DF4E1A4B4D95.mlw
sha1: adfd44ccb9241843d5487cfa18edd6430ba33355
sha256: 77be0548a2da304349c668a5a5674c7fb5005ffa46d1f71a519eab354002f45e
sha512: 2b3bcf9034ed1ec5dfbd0415daadbbed249eef1bf7361418900bd155023e5e3c0619813af6e3c867a85594519a4662af7c6daa5941253f6aeba115689e9226b5
ssdeep: 6144:y/sJ+MFkv1NN4g0IreeeeeeeHHHHHHHHOhU+:xSmg0IreeeeeeeHHHHHHHHkZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: windows11-updates.iso
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: windows11-updates.iso

Tatrio.4 also known as:

K7AntiVirusTrojan ( 0051c2441 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.26652
CynetMalicious (score: 99)
ALYacGen:Variant.Tatrio.4
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0051c2441 )
Cybereasonmalicious.d69019
BaiduMSIL.Trojan-Dropper.Binder.a
CyrenW32/MSIL_Binder.A.gen!Eldorado
SymantecRansom.Petya
ESET-NOD32a variant of MSIL/TrojanDropper.Binder.CA
APEXMalicious
AvastMBR:Ransom-C [Trj]
ClamAVWin.Ransomware.Petya-6992434-0
KasperskyTrojan-Ransom.Win32.Petr.aqv
BitDefenderGen:Variant.Tatrio.4
NANO-AntivirusTrojan.Win32.Agent.dzsrep
MicroWorld-eScanGen:Variant.Tatrio.4
Ad-AwareGen:Variant.Tatrio.4
SophosML/PE-A + Troj/dnsauce-B
ComodoTrojWare.MSIL.TrojanDropper.Binder.CA@7nerge
BitDefenderThetaGen:NN.ZemsilF.34758.xm0@aSzWXib
TrendMicroTROJ_BINDER.SMA
McAfee-GW-EditionBehavesLike.Win32.Dropper.fm
FireEyeGeneric.mg.d57281cd6901962d
EmsisoftGen:Variant.Tatrio.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bcpht
AviraBDS/Bladabindi.alif
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Tatrio.4
ZoneAlarmHEUR:Trojan.MSIL.Tpyn.gen
GDataGen:Variant.Tatrio.4
MAXmalware (ai score=84)
VBA32TrojanRansom.Petr
MalwarebytesMalware.AI.3621153645
TrendMicro-HouseCallTROJ_BINDER.SMA
RisingTrojan.Runp!1.9DFA (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Dropper_Binder.BS!tr
AVGMBR:Ransom-C [Trj]

How to remove Tatrio.4?

Tatrio.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment