Trojan

How to remove “Trojan.Win32.Vilsel.drmu”?

Malware Removal

The Trojan.Win32.Vilsel.drmu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vilsel.drmu virus can do?

  • Uses Windows utilities for basic functionality
  • Modifies host OEM information
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Accessed credential storage registry keys
  • Disables Windows Notification Center
  • Attempts to disable UAC
  • Attempts to modify user notification settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Vilsel.drmu?


File Info:

name: 88119A6D1C51E2C02EB4.mlw
path: /opt/CAPEv2/storage/binaries/007be0fb0f63ea121ae7614c578c2c60e1a36b674b48435d1f8972f14a943eae
crc32: C84D193B
md5: 88119a6d1c51e2c02eb442e405cb01b0
sha1: da9b815b8120b14b709b48f54d0f15ddd2f35eea
sha256: 007be0fb0f63ea121ae7614c578c2c60e1a36b674b48435d1f8972f14a943eae
sha512: 7ee6f82df2e67b00d4ff91fefbfc33e26306384428c50c039cd92693b5329e4f1ab9e09724c80219e12c3b40b8730d81f30d1c8ed26a02ceda2d2557ac1447b1
ssdeep: 49152:2h+ZkldoPK8YaWmowEkClAvCBDa0yUhfdp:v2cPK8kbwyyiaQVd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19995D00367D1F062FF9A45735F75A3214EB86D66A523CD5F22E43A6EBA310E1132D223
sha3_384: 7baad5f84037b4d62b895ee11a27770136d64cdb8f375f422228e212f7bfce671cc482748f135d3f70af6f19296ef173
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2018-11-14 02:39:46

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.Vilsel.drmu also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vilsel.4!c
tehtrisGeneric.Malware
DrWebTrojan.MulDrop21.20255
MicroWorld-eScanTrojan.GenericKD.64032298
ALYacTrojan.GenericKD.64032298
SangforTrojan.Win32.Agent.Viwu
K7AntiVirusTrojan ( 0054f1d81 )
AlibabaTrojan:Win32/Vilsel.4522a805
K7GWTrojan ( 0054f1d81 )
CrowdStrikewin/malicious_confidence_60% (D)
VirITTrojan.Win32.Packed2.CJLD
CyrenW32/AutoIt.OH.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.Autoit.NAZ suspicious
APEXMalicious
KasperskyTrojan.Win32.Vilsel.drmu
BitDefenderTrojan.GenericKD.64032298
AvastWin32:Malware-gen
TencentWin32.Trojan.Vilsel.Kzfl
EmsisoftTrojan.GenericKD.64032298 (B)
F-SecureHeuristic.HEUR/AGEN.1319338
VIPRETrojan.GenericKD.64032298
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeTrojan.GenericKD.64032298
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.64032298
GoogleDetected
AviraHEUR/AGEN.1319338
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Autoit.BinToStr.a
Kingsoftmalware.kb.a.875
ArcabitTrojan.Generic.D3D10E2A
ZoneAlarmTrojan.Win32.Vilsel.drmu
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C3272894
Cylanceunsafe
PandaTrj/CI.A
MaxSecureTrojan.Malware.74329405.susgen
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Vilsel.drmu?

Trojan.Win32.Vilsel.drmu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment