Trojan

Trojan-Dropper.Win32.Gamaredon.adq (file analysis)

Malware Removal

The Trojan-Dropper.Win32.Gamaredon.adq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Gamaredon.adq virus can do?

  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Makes SMTP requests, possibly sending spam or exfiltrating data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
nexusrules.officeapps.live.com
config.edge.skype.com
smtps.bol.com.br

How to determine Trojan-Dropper.Win32.Gamaredon.adq?


File Info:

crc32: 30F7362C
md5: 12bb11b9cb2c85ad1bb8895fd51fcceb
name: 12BB11B9CB2C85AD1BB8895FD51FCCEB.mlw
sha1: 47d768a7e8f2cebca881a878697ad10210367312
sha256: 8c5cd0417bca0737e9981f2fab63f1beaeafd9a55d4df24444d90c107deb44ba
sha512: 8a3c783df5f8b86edb87a43030496f657bc21459d6aff77b66ae7faf02b624d2b4207f3894a5e23b599a7803207eb37a874e5f240a168a660d88521d732eca3b
ssdeep: 196608:WLcDHK47+f+mFWIMBXAGoi8fsU1mqBTt+a4imKHbK:WLcDHa2EMBwo8EU11Tt3LO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Dropper.Win32.Gamaredon.adq also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004befdb1 )
LionicTrojan.Win32.Encoder.tq0V
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.54173
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.42888859
CylanceUnsafe
ZillyaTrojan.Rasftuby.Win32.316
K7GWTrojan ( 004befdb1 )
Cybereasonmalicious.9cb2c8
CyrenW32/Trojan.GMR.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Bladabindi-6813690-0
KasperskyTrojan-Dropper.Win32.Gamaredon.adq
BitDefenderTrojan.GenericKD.42888859
NANO-AntivirusTrojan.Win32.Vimditator.hgyowa
MicroWorld-eScanTrojan.GenericKD.42888859
TencentWin32.Trojan-dropper.Gamaredon.Dxxb
Ad-AwareTrojan.GenericKD.42888859
SophosMal/Generic-S
ComodoMalware@#1wnae9od54r8a
F-SecureTrojan.TR/Vimditator.wqsjy
BitDefenderThetaGen:NN.ZedlaF.34266.N28@aWWUmPji
TrendMicroTROJ_GEN.R007C0DH721
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.12bb11b9cb2c85ad
EmsisoftTrojan.GenericKD.42888859 (B)
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.Scrami.s
AviraTR/Vimditator.wqsjy
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftTrojan:Win32/Occamy.C8C
ArcabitTrojan.Generic.D28E6E9B
GDataWin32.Trojan.Agent.2X43UX
AhnLab-V3Malware/Win32.RL_Generic.R305028
McAfeeArtemis!12BB11B9CB2C
MAXmalware (ai score=87)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.749428179
PandaTrj/CI.A
RisingTrojan.Generic@ML.100 (RDMK:1kf/IiUUu8dAQqnKk7ymnA)
FortinetRiskware/Gamaredon
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Dropper.Win32.Gamaredon.adq?

Trojan-Dropper.Win32.Gamaredon.adq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment