Trojan

Trojan.Orsam.A4 (file analysis)

Malware Removal

The Trojan.Orsam.A4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Orsam.A4 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • A scripting utility was executed

How to determine Trojan.Orsam.A4?


File Info:

name: A0ED2775E18EB9F17F3C.mlw
path: /opt/CAPEv2/storage/binaries/570f5ad2379273f9f51f33a103dd27c403925e81efbf273f9eea3cb6e76dd9b6
crc32: 8B01E642
md5: a0ed2775e18eb9f17f3cd45f877b0059
sha1: 6731db5bccbe82fe3791853445e4046205860ee5
sha256: 570f5ad2379273f9f51f33a103dd27c403925e81efbf273f9eea3cb6e76dd9b6
sha512: 4ef1f6f1085edbc717918472d8226bec4dfb791c987d651a60a9dd315e320076721f01e4221d780052fa1a19c0ab833928aa5ef654bf039d2e18cb837820084c
ssdeep: 12288:yzy6rRxEfbpnfkjuVtPuVcG6YO/uV1ObuVtFnvysf1Q1TkAQTuiHCXLgd/qi1:56rTgbp8iVtGVcG9pV1OqVtFnSQT3iQ7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164E40115FF8640B3C4400B3158EE6236E33AFF062971E69C9BA97C25E8F5502A45DBB6
sha3_384: 6e38fe191f0deda71cb3793894bd6a0e8fe14f53f09398cce1b43e86c25fada8f0c1b55706ccc7146452e6df7f2adc6e
ep_bytes: e82f2b000050e83f3101000000000090
timestamp: 2007-05-22 04:59:14

Version Info:

0: [No Data]

Trojan.Orsam.A4 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Sola.Gen
ClamAVWin.Trojan.Pcclient-4245
FireEyeGeneric.mg.a0ed2775e18eb9f1
CAT-QuickHealTrojan.Orsam.A4
ALYacWin32.Sola.Gen
CylanceUnsafe
VIPREWin32.Sola.Gen
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004c4cd31 )
K7GWTrojan ( 004c4cd31 )
Cybereasonmalicious.5e18eb
BaiduWin32.Trojan.Generic.u
VirITTrojan.Win32.MulDrop4.BZUC
CyrenW32/Imaut.A.gen!Eldorado
SymantecW32.SillyDC
ESET-NOD32multiple detections
APEXMalicious
AvastVBS:Agent-ED [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Script.Jobber.d
BitDefenderWin32.Sola.Gen
NANO-AntivirusTrojan.Win32.PcClient.dgwtmn
SUPERAntiSpywareTrojan.Agent/Gen-PCClient
TencentVirus.Win32.SOLA.c
Ad-AwareWin32.Sola.Gen
EmsisoftWin32.Sola.Gen (B)
ComodoBackdoor.Win32.PcClient.~dy006@1xbo78
DrWebBackDoor.PcClient.3131
TrendMicroTROJ_AGENT_EK16009E.UVPM
McAfee-GW-EditionTrojan-FDJM!A0ED2775E18E
SophosMal/Generic-R
JiangminTrojan/RarDocument.c
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASSuf.414D4
KingsoftWin32.Troj.DeepScan.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotBackdoor.Win32.PcClient.844896
GDataWin32.Sola.Gen
GoogleDetected
AhnLab-V3Dropper/PcClient.Gen
McAfeeTrojan-FDJM!A0ED2775E18E
MAXmalware (ai score=89)
VBA32Win32.Trojan.Dropper.Heur
MalwarebytesTrojan.Dropper.SFXAI
TrendMicro-HouseCallTROJ_AGENT_EK16009E.UVPM
RisingVirus.Sola/BAT!1.A24F (CLASSIC)
YandexBackdoor.PcClient!Whun8uuq72A
IkarusVirus.BAT.Agent
FortinetW32/PcClient.FED!tr
BitDefenderThetaAI:FileInfector.49B167EC0E
AVGVBS:Agent-ED [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Orsam.A4?

Trojan.Orsam.A4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment