Trojan

Trojan.Win32.Vilsel removal

Malware Removal

The Trojan.Win32.Vilsel is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vilsel virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Attempts to disable or modify Explorer Folder Options
  • Disables host Power options (shutdown, logoff, lock, change password)
  • Attempts to disable or modify the Run command from the Start menu and the New Task (Run) command from Task Manager
  • Attempts to block SafeBoot use by removing registry keys
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Vilsel?


File Info:

name: A45DFF5D77112435BAFF.mlw
path: /opt/CAPEv2/storage/binaries/9798a81daf8f4663c643cf4d4308730d457c44160eb270f793b4380354af4bee
crc32: 84CE6E74
md5: a45dff5d77112435baffbb8531e43c90
sha1: 2aa9f43a98c53c7f7e4dbca288ff4746fef5332f
sha256: 9798a81daf8f4663c643cf4d4308730d457c44160eb270f793b4380354af4bee
sha512: ad0d54de8ba0fdecab6ad9647b3812c1c32b7fd5bdfb21a7012a6080619a8c9583f95c7cca294b911423295627b9e31334b8cce7a9cb706cb1a3231d4e4f8142
ssdeep: 49152:nIdqiphXfbu2KkUkCNcTh5xdPmFtdrD5PtnoPB/t+aZ/yFF:nkp9fbu2KNNwJBmFtdH56PB/HJy/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DD5DFE1F58584B1CC272D380826BF768533AEA67F29C6837258FE95AB732C35532057
sha3_384: 4008ceaa078eb171ff7194d5652950c43c88c9139031414bfc4fe2533ff26d399b957ebb3a37763a23c9434d399deba6
ep_bytes: 558bec6aff68e8f46600681c71480064
timestamp: 2021-08-20 09:29:22

Version Info:

0: [No Data]

Trojan.Win32.Vilsel also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.a45dff5d77112435
McAfeeArtemis!A45DFF5D7711
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.34182.QsW@aCR60@bb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Disabler.NAV
KasperskyHEUR:Trojan.Win32.Vilsel.gen
AvastWin32:Dh-A [Heur]
TencentWin32.Trojan.Bp-antiav.Oerb
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
APEXMalicious
JiangminHeur:Trojan/AntiAV
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.Win32.Vilsel.gen
GDataWin32.Trojan.PSE.1THOGOA
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4956486
MalwarebytesTrojan.MalPack.FlyStudio
RisingTrojan.Disabler!1.BB16 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Disabler.NAT!tr
AVGWin32:Dh-A [Heur]
Cybereasonmalicious.a98c53
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Vilsel?

Trojan.Win32.Vilsel removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment