Malware

Troj/DwnLdr-VVP removal instruction

Malware Removal

The Troj/DwnLdr-VVP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DwnLdr-VVP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Queries information on disks, possibly for anti-virtualization
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Troj/DwnLdr-VVP?


File Info:

name: 2196FF244731DD77435A.mlw
path: /opt/CAPEv2/storage/binaries/116b6154d04260ca235db78f2abbc647cc80b92a9838360eaee4f3b8eb50d5c8
crc32: 3D6EDCD4
md5: 2196ff244731dd77435a76b110ca1901
sha1: a2d5d686b96f9422901511b7a492bc065097904a
sha256: 116b6154d04260ca235db78f2abbc647cc80b92a9838360eaee4f3b8eb50d5c8
sha512: 2c4591aaca1248838c19fada9ec9d306db25d2483c5100f02563ef38642b7c07993379c8635b41c2d45793e3c4a7dd035d0c487e3c0fd784fa430166b062f7ce
ssdeep: 12288:ChkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcE4a+6v/1+FM6L13EoHQ:iRmJkcoQricOIQxiZY1ia+AaM6tEoHQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13315B021F5C69036C2B323B19E7EF776963D6D360326D29727C42E237EA05416B29723
sha3_384: 501a359b8f8331fbd88d6d58c4ed803ecb6d176c25977a9e801d241b5fbd37dc652b28cb37c2c61800f0a01c7d16b9de
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Troj/DwnLdr-VVP also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.lrP4
CynetMalicious (score: 100)
FireEyeGeneric.mg.2196ff244731dd77
McAfeeGeneric.atv
CylanceUnsafe
VIPRETrojan.GenericKD.3816916
SangforTrojan.Win32.Autoit.CV
K7AntiVirusTrojan ( 005057c11 )
AlibabaTrojanSpy:Script/DwnLdr.3980e4f7
K7GWTrojan ( 005057c11 )
Cybereasonmalicious.44731d
CyrenW32/AutoIt.MQSN-3517
SymantecTrojan.Lodarat
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.DarkKomet-9917549-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.3816916
NANO-AntivirusTrojan.Win32.Autoit.ejolmh
MicroWorld-eScanTrojan.GenericKD.3816916
TencentAutoit.Trojan.Psw.Hpry
Ad-AwareTrojan.GenericKD.3816916
SophosTroj/DwnLdr-VVP
ComodoMalware@#otscgnb8jovp
DrWebTrojan.DownLoader23.26465
ZillyaTrojan.GenericKD.Win32.21443
TrendMicroTSPY_INFOSTEAL.SM
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.3816916 (B)
GDataTrojan.GenericKD.3816916
JiangminTrojan.PSW.Autoit.aj
WebrootPua.Gen
AviraHEUR/AGEN.1229397
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D3A3DD4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
AhnLab-V3Malware/Win32.Generic.C1676210
ALYacTrojan.GenericKD.3816916
MAXmalware (ai score=96)
VBA32Trojan.Autoit.F
MalwarebytesGeneric.Trojan.Malicious.DDS
TrendMicro-HouseCallTSPY_INFOSTEAL.SM
RisingTrojan.Obfus/Autoit!1.BEDE (CLASSIC)
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.BQ!tr
BitDefenderThetaAI:Packer.9BBE153515
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/DwnLdr-VVP?

Troj/DwnLdr-VVP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment