Trojan

What is “Trojan.Win32.Vasal.cpn”?

Malware Removal

The Trojan.Win32.Vasal.cpn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vasal.cpn virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Trojan.Win32.Vasal.cpn?


File Info:

name: 22AF2EED547864DC90CE.mlw
path: /opt/CAPEv2/storage/binaries/53d13d7dc59da6e4998c4c81ba9994e15096b3b70d64bea064550c3868b27851
crc32: 3EEFE0E4
md5: 22af2eed547864dc90ce4dd6de5a373e
sha1: 74a107fe55bb689a89d91272729b80e45cabee0b
sha256: 53d13d7dc59da6e4998c4c81ba9994e15096b3b70d64bea064550c3868b27851
sha512: d313622cd806e275872c011baed900cdf6446063f5b95a4d3318a3b3a518fc111f12b0c5e204211fcd07e3511b848cd71cb05821103d8255ee79238f8f4fb721
ssdeep: 24576:U2G/nvxW3Ww0t+MJT4DFJOISgvsVI8HcRG7+e:UbA30+MJT4DzOzVrHL7x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151050201BAC18572D2311E364A2DAB51653DBD201F28DEEF93E46A6DDA301C0FE35B67
sha3_384: 563faa8d53c29bacc3202fdf241b76b5028490bbdaa47d225c34ce63ca31ff4658554ca6c581849e502750417874232d
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Trojan.Win32.Vasal.cpn also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Makop.trQA
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Uztuby.17
McAfeeArtemis!22AF2EED5478
CylanceUnsafe
SangforTrojan.BAT.Runner.EG
K7AntiVirusTrojan ( 0056839f1 )
BitDefenderTrojan.Uztuby.17
K7GWTrojan ( 0056839f1 )
Cybereasonmalicious.d54786
CyrenW32/S-1b09bef6!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/Runner.EG
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vasal.cpn
AlibabaTrojan:Win32/Vasal.15383e16
Ad-AwareTrojan.Uztuby.17
EmsisoftTrojan.Uztuby.17 (B)
VIPRETrojan.Uztuby.17
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.22af2eed547864dc
SophosMal/RarMal-R
WebrootW32.Trojan.Gen
AviraTR/Runner.jqrow
MicrosoftRansom:MSIL/Gorf
GDataWin32.Trojan.BSE.1CL7UZW
GoogleDetected
AhnLab-V3Trojan/Win.Uztuby.C4510393
ALYacTrojan.Zmutzy.Lscpt.1
MAXmalware (ai score=83)
VBA32Trojan.Vasal
MalwarebytesTrojan.Dropper.SFX
PandaTrj/CI.A
TencentWin32.Trojan.Vasal.Twhl
IkarusTrojan.Rasftuby
MaxSecureTrojan.Malware.74071018.susgen
FortinetW32/Uztuby.17!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Vasal.cpn?

Trojan.Win32.Vasal.cpn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment