Trojan

Trojan:MSIL/Vigorf.A malicious file

Malware Removal

The Trojan:MSIL/Vigorf.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Vigorf.A virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan:MSIL/Vigorf.A?


File Info:

crc32: DBB9C390
md5: a1b276dd46064618b63e96c87b02b7f6
name: setup.exe
sha1: 80bd6fff8a3aa93b505c0b3136a847bd35bbf38c
sha256: ba400b6e539777af21fd5bd745f67bdfd33090cf76618f2be337c04a1179917d
sha512: 2ce41cb76285e13a59d8b36f695edda7549aacf423a5e8aa3ad4d1348552c3478b9adfecfceafdf4a331a587821a9a5e8826eefd6d2973b5d985675c6630dd7f
ssdeep: 24576:EZ1wGs+1jRaPS25BxfWlNhAER9j9Bkdl02U+yKW6nIvRaRYny/rmVn:EZ1wGs+1Yn/VWrvpBknU+yKGaIy/Sn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2008 - 2019
Assembly Version: 0.0.0.0
InternalName: file.exe
FileVersion: 7.10.14.18
CompanyName: o$7B}8PgF!y5*q2E9
Comments: Pp9+x=G8*5mQ2
ProductName: tQ$6G{7o8i-P/Yn3
ProductVersion: 7.10.14.18
FileDescription: tQ$6G{7o8i-P/Yn3
OriginalFilename: file.exe

Trojan:MSIL/Vigorf.A also known as:

MicroWorld-eScanGen:Variant.Ursu.758538
McAfeeArtemis!A1B276DD4606
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Ursu.758538
K7GWTrojan ( 005609dd1 )
K7AntiVirusTrojan ( 005609dd1 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34090.Er2@aS3P63cj
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DangerousSig [Trj]
GDataGen:Variant.Ursu.758538
KasperskyHEUR:Trojan-PSW.MSIL.Predator.gen
AlibabaTrojanPSW:MSIL/Injector.f9700666
AegisLabTrojan.Win32.Ursu.4!c
RisingTrojan.Injector!8.C4 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ursu.758538 (B)
F-SecureTrojan.TR/Dropper.MSIL.aaaajo
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.a1b276dd46064618
SophosMal/Generic-S
IkarusTrojan.MSIL.Injector
AviraTR/Dropper.MSIL.aaaajo
MAXmalware (ai score=89)
MicrosoftTrojan:MSIL/Vigorf.A
ArcabitTrojan.Ursu.DB930A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Predator.gen
AhnLab-V3Malware/Win32.Generic.C959857
ALYacGen:Variant.Ursu.758538
Ad-AwareGen:Variant.Ursu.758538
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.USG
TencentWin32.Trojan.Falsesign.Lmak
SentinelOneDFI – Suspicious PE
FortinetMSIL/Predator!tr.pws
WebrootW32.Adware.Gen
AVGWin32:DangerousSig [Trj]
Cybereasonmalicious.f8a3aa
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.9ad

How to remove Trojan:MSIL/Vigorf.A?

Trojan:MSIL/Vigorf.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment