Spy Trojan

What is “TrojanSpy:Win32/Vwealer.IZ”?

Malware Removal

The TrojanSpy:Win32/Vwealer.IZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Vwealer.IZ virus can do?

  • Executable code extraction
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

www.soltanzadezarand.com

How to determine TrojanSpy:Win32/Vwealer.IZ?


File Info:

crc32: 9707EDB2
md5: b287cb049797364d017084a6ea24265e
name: B287CB049797364D017084A6EA24265E.mlw
sha1: 10f5e8add1dddd5c62f45ad46d59f2eb12e870c9
sha256: a4103c6beb986d965bd69d3d6ee9ed08c4fd50a695d5e9a9010f756be88f313d
sha512: 92f1f107ce5d7315cda984c6fa2e277300b62dc58589eea5d9c8affc5981f157812f2580dfe8e5d982f9c6bd1fa1fd0fa263c936e8cb16536fd2e77cb7d6b0f2
ssdeep: 3072:qPoHQjNKKS736/6KrN7m8JQU0G8nMhXdXKSgbCcHmqMCKQosgu1LHX:qwH+wJLwHN+PBMhXdKSgbRGqcQos
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright:
InternalName: randy2
FileVersion: 1.00
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.00
FileDescription:
OriginalFilename: randy2.exe

TrojanSpy:Win32/Vwealer.IZ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusNetWorm ( 700000151 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.59705
CynetMalicious (score: 100)
McAfeeGeneric Keylogger.r
CylanceUnsafe
ZillyaTrojan.Regrun.Win32.5946
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/PornoAsset.04f71dd3
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.497973
CyrenW32/VB.BN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.VB.BET
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-85387
KasperskyTrojan-Ransom.Win32.PornoAsset.czgt
BitDefenderGen:Application.Keylog.mu0@aK0NcLdi
NANO-AntivirusTrojan.Win32.PornoAsset.fknjds
MicroWorld-eScanGen:Application.Keylog.mu0@aK0NcLdi
TencentWin32.Trojan.Pornoasset.Pefn
Ad-AwareGen:Application.Keylog.mu0@aK0NcLdi
SophosML/PE-A + Troj/IMPWS-Gen
ComodoTrojWare.Win32.Regrun.E@1ofvk9
F-SecureTrojan.TR/Dropper.Gen
BitDefenderThetaAI:Packer.7F59CE8420
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.b287cb049797364d
EmsisoftGen:Application.Keylog.mu0@aK0NcLdi (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2973D95
MicrosoftTrojanSpy:Win32/Vwealer.IZ
AegisLabTrojan.Win32.PornoAsset.4!c
ZoneAlarmTrojan-Ransom.Win32.PornoAsset.czgt
GDataGen:Application.Keylog.mu0@aK0NcLdi
Acronissuspicious
VBA32TScope.Trojan.VB
MAXmalware (ai score=79)
PandaTrj/CI.A
RisingRansom.PornoAsset!8.6AA (CLOUD)
YandexTrojan.GenAsa!3OUEUZUljTA
IkarusTrojan.Win32.Regrun
FortinetW32/PornoAsset.CZGT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Vwealer.IZ?

TrojanSpy:Win32/Vwealer.IZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment