Trojan

TrojanDropper:MSIL/Habbo.A (file analysis)

Malware Removal

The TrojanDropper:MSIL/Habbo.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:MSIL/Habbo.A virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDropper:MSIL/Habbo.A?


File Info:

crc32: 8EDD6D17
md5: c795a485df6f97629bf1f5319d207d83
name: windowsrefund.exe
sha1: 8185d313dbc8f73c5fd82e7c3b0e0157828514c6
sha256: f150bdb4a455bcec6cafa42460882cf6d939282821bfff31ae468f6a6f9e7769
sha512: 023716cad464413eb960f5b7e4cd5b6e0d8060ed34ccc7fb00a9ad7af7d0e714877aa9bf92c73c37e4e6bccb859e83cc124f086c1d2389edd220db323ad57b39
ssdeep: 6144:FO+zrEsiN1PPzS97xl1Ipzn/rbOLK1r7lnCv9cf2cy3dhWFKQQI4YsFBpNrg+x9:kxsiN497xlKN/uLK13lnCv+BX1ql
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: WindowsRefund.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: WindowsRefund.exe

TrojanDropper:MSIL/Habbo.A also known as:

DrWebTrojan.PWS.Siggen.27583
MicroWorld-eScanGen:Variant.MSILKrypt.11
FireEyeGeneric.mg.c795a485df6f9762
CAT-QuickHealTrojan.MsilFC.S6053757
Qihoo-360Generic/Trojan.bc3
McAfeeGenericRXAF-WW!C795A485DF6F
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0011d83e1 )
BitDefenderGen:Variant.MSILKrypt.11
K7GWTrojan ( 0011d83e1 )
Cybereasonmalicious.5df6f9
TrendMicroTrojan.Win32.HABBO.SM
BitDefenderThetaGen:NN.ZemsilF.34090.4m0@a4VGe0f
CyrenW32/MSIL_Troj.L.gen!Eldorado
TotalDefenseWin32/MultiDropper.QQ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-6295765-0
GDataGen:Variant.MSILKrypt.11
KasperskyTrojan.MSIL.Agent.foww
AlibabaTrojanDropper:MSIL/Habbo.1058c931
NANO-AntivirusTrojan.Win32.Zapchast.dcmmdd
ViRobotTrojan.Win32.Z.Habbo.917504
TencentMsil.Trojan.Agent.Szld
Ad-AwareGen:Variant.MSILKrypt.11
SophosTroj/Subti-A
ComodoTrojWare.MSIL.TrojanDropper.Agent.~Ajv@1zen4r
F-SecureTrojan.TR/Dropper.Gen2
VIPRETrojan-Dropper.Win32.Habbo.a (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cm
Trapminemalicious.high.ml.score
CMCTrojan-Dropper.MSIL.Agent!O
EmsisoftGen:Variant.MSILKrypt.11 (B)
IkarusVirus.Win32.Prorat
F-ProtW32/MSIL_Troj.L.gen!Eldorado
JiangminTrojanDropper.MSIL.cmg
AviraTR/Dropper.Gen2
MAXmalware (ai score=81)
Endgamemalicious (high confidence)
ArcabitTrojan.MSILKrypt.11
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDropper:MSIL/Habbo.A
AhnLab-V3Trojan/Win32.RL_Agent.C3633925
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.MSILKrypt.11
MalwarebytesBackdoor.IRCBot.OLGen
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.AST
TrendMicro-HouseCallTrojan.Win32.HABBO.SM
RisingBackdoor.Quasar!1.B1DD (CLOUD)
YandexTrojan.DR.Agent!cAmBb9WNsbI
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
FortinetMSIL/Dropper.JV!tr
AVGMSIL:Rat-B [Trj]
AvastMSIL:Rat-B [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureDropper.Agent.ajv

How to remove TrojanDropper:MSIL/Habbo.A?

TrojanDropper:MSIL/Habbo.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment