Trojan

What is “Trojan:Win32/LimeRat.A!cert”?

Malware Removal

The Trojan:Win32/LimeRat.A!cert is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LimeRat.A!cert virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/LimeRat.A!cert?


File Info:

crc32: D6B6F6E8
md5: 09dfe85d9588103e101da96351845073
name: upload_file
sha1: 217820a3d1c1b03d38acd760590e8c2db42ed553
sha256: 7952bdc31aff90112f8b774602374bec264496134716b132cfbc832107fd15fe
sha512: 444dd197c34981a3c51e1c80e94f7a306d5bc27f924084228ff0d01ea479275ec505b974beb7e5e6331f15c9abd8c4a33a1a1582c55c6576b555d5071b9b5385
ssdeep: 3072:Dht6sYlB2+GBER/BDSscD4aJlmJaAyriytk6+5rRLIduvWnPwcsLbPft4Tl+4Q/c:Ft6sYlB2+GBER/BDSscD4aJlmJaAyrig
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 3.6.0.0
InternalName: vbc.exe
FileVersion: 3.600.20.25105
CompanyName: Microsoft Corporation
ProductName: vbc
ProductVersion: 3.6.0-4.20251.5+910223b64f108fcf039012e0849befb46ace6e66
FileDescription: vbc
OriginalFilename: vbc.exe

Trojan:Win32/LimeRat.A!cert also known as:

MicroWorld-eScanTrojan.GenericKD.34389024
FireEyeGeneric.mg.09dfe85d9588103e
CAT-QuickHealTrojan.Multi
ALYacTrojan.MSIL.LimeRAT
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2379297
AegisLabTrojan.MSIL.Androm.m!c
SangforMalware
K7AntiVirusTrojan ( 0056cdda1 )
BitDefenderTrojan.GenericKD.34389024
K7GWTrojan ( 0056cdda1 )
CrowdStrikewin/malicious_confidence_80% (D)
InvinceaMal/Generic-S
CyrenW32/Trojan.JNRT-2624
SymantecTrojan Horse
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaBackdoor:Win32/LimeRat.9659705d
NANO-AntivirusTrojan.Win32.Androm.hsjcpp
Ad-AwareTrojan.GenericKD.34389024
F-SecureTrojan.TR/Kryptik.ojgms
DrWebTrojan.DownLoader29.2373
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.WACATAC.USXVPHK20
MaxSecureTrojan.Malware.73691364.susgen
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminBackdoor.MSIL.dokx
WebrootW32.Trojan.Gen
AviraTR/Kryptik.ojgms
MAXmalware (ai score=83)
Antiy-AVLTrojan/MSIL.Kryptik
MicrosoftTrojan:Win32/LimeRat.A!cert
ArcabitTrojan.Generic.D20CBC20
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.GenericKD.34389024
McAfeeTrojan-FTAB!09DFE85D9588
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.FakeMS
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.XJU
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPHK20
TencentWin32.Trojan.Falsesign.Ijf
IkarusTrojan.Inject
FortinetMSIL/Kryptik.XJP!tr
BitDefenderThetaGen:NN.ZemsilF.34216.jm1@a42ldUe
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.3d1c1b
Qihoo-360Generic/Backdoor.9cf

How to remove Trojan:Win32/LimeRat.A!cert?

Trojan:Win32/LimeRat.A!cert removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment