Trojan

Trojan-PSW.Win32.Vidar.bni information

Malware Removal

The Trojan-PSW.Win32.Vidar.bni is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Vidar.bni virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location

How to determine Trojan-PSW.Win32.Vidar.bni?


File Info:

name: 3FD60252A36F8210069C.mlw
path: /opt/CAPEv2/storage/binaries/6b69e098de48b354e7d8f1f201461c801da42a3052a73d36153f8e4520120a46
crc32: 04D10452
md5: 3fd60252a36f8210069c52ccbb4eb10a
sha1: ecc3fe4c55ea937d5951a051cc0687eb0c582214
sha256: 6b69e098de48b354e7d8f1f201461c801da42a3052a73d36153f8e4520120a46
sha512: a72cda4562e886bfd4321ca5e821c3993e2ded74b9edcb2c4e2ee59012c42ad0697f47ea2ecbf22e4ff2c8eaafdeb4b2780c3149daaa802ecca293cc4866739e
ssdeep: 12288:ocEeL81m5u0m4/+ZUNTOeVqnuDTX4k2UKJW5zB:gg8o5u6iUNTOeV+u/ok2UH5zB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144052AB4B1E1E17AC90141301925BE7197F45DA0DE72A9A3EEDCFAE4E430DE12B36706
sha3_384: 74efdb8b489c39a14ddf65bc90d1b7c920b94effcd67e15629791a6e8b9fe9e405bbc3f599a3e85310069050f283b66d
ep_bytes: 558bec6aff6870984400686cc1430064
timestamp: 2014-09-14 02:37:03

Version Info:

CompanyName: $cn
FileDescription: Microsoft Word document
FileVersion: 9.3.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename: document.exe
PrivateBuild:
ProductName: Document
ProductVersion: 6.4.3.1
SpecialBuild:
Comments: Modified by an unpaid evaluation copy of Resource Tuner Console 2. http://www.heaventools.com
Translation: 0x0409 0x04b0

Trojan-PSW.Win32.Vidar.bni also known as:

LionicTrojan.Win32.Vidar.i!c
DrWebTrojan.PWS.Siggen2.51398
MicroWorld-eScanTrojan.GenericKD.38223387
McAfeeArtemis!3FD60252A36F
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 00565c251 )
AlibabaTrojanPSW:Win32/Vidar.0a86e19b
K7GWPassword-Stealer ( 00565c251 )
BitDefenderThetaGen:NN.ZexaF.34084.Xq3@ayLxjjli
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Agent.OJQ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-PSW.Win32.Vidar.bni
BitDefenderTrojan.GenericKD.38223387
NANO-AntivirusTrojan.Win32.Banload.fmzjkk
TencentWin32.Trojan-qqpass.Qqrob.Lplu
Ad-AwareTrojan.GenericKD.38223387
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.bm
FireEyeTrojan.GenericKD.38223387
EmsisoftTrojan.GenericKD.38223387 (B)
Paloaltogeneric.ml
GDataTrojan.GenericKD.38223387
AviraTR/PSW.Agent.yotqi
ArcabitTrojan.Generic.D2473E1B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
VBA32Trojan.Downloader
ALYacTrojan.GenericKD.38223387
MAXmalware (ai score=88)
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R002H0DL821
IkarusTrojan-PSW.Agent
FortinetW32/Agent.OJQ!tr.pws
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-PSW.Win32.Vidar.bni?

Trojan-PSW.Win32.Vidar.bni removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment