Trojan

Should I remove “Trojan:Win32/Sisrop!rts”?

Malware Removal

The Trojan:Win32/Sisrop!rts is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sisrop!rts virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Sisrop!rts?


File Info:

name: 31A1E12C22757791426F.mlw
path: /opt/CAPEv2/storage/binaries/e3b5a667b9bf14acbaa38946637b8f2528fbca8326790d9708ad54e25a303964
crc32: 1503464B
md5: 31a1e12c22757791426fab9c8fc79171
sha1: 3e27d5ecb05fb2cac2ca5634dd71a4f5276cce69
sha256: e3b5a667b9bf14acbaa38946637b8f2528fbca8326790d9708ad54e25a303964
sha512: 81537e6b24556208508d75f61b7d333ba246add92726b9285720df739828b0e25280ad2c7d339e86d124135de91feefa3803df31b44201dba2d5981b9c722740
ssdeep: 6144:v/4Hx5HR34FZg7aejHUM8J+HWbRwANTlWsnK:Y5Ht4F2H0MG4W1u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD3412D4FEAC1821C8B658FB460EC734BF91B5A396440BC38650AC2F3D352592BC2B96
sha3_384: faf34f095cf9741f62da35843461a6d5716c7dea4f354cab5f06afd19841d3576163765d302007e1669749d2f3811733
ep_bytes: 60be000046008dbe0010faffc7870cd7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Sisrop!rts also known as:

BkavW32.Common.62E63ECA
LionicTrojan.Win32.FakeHotmail.4!c
MicroWorld-eScanApplication.Generic.7570
FireEyeApplication.Generic.7570
SkyhighGenericR-HII!C97F779F8F92
McAfeeArtemis!31A1E12C2275
Cylanceunsafe
ZillyaTrojan.FakeHotmail.Win32.2
AlibabaTrojan:Win32/Generic.8110a9eb
BitDefenderThetaGen:NN.ZelphiF.36744.omGfaKljbImi
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.LUWYIRO
APEXMalicious
ClamAVWin.Trojan.Fakehotmail-3
KasperskyTrojan.Win32.Scar.kmwr
BitDefenderApplication.Generic.7570
NANO-AntivirusTrojan.Win32.FakeHotmail.rfvs
AvastWin32:Trojan-gen
RisingTrojan.Sisrop!8.2DA6 (TFE:5:T4U3VTvG1YK)
EmsisoftApplication.Generic.7570 (B)
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.Siggen3.28892
VIPREApplication.Generic.7570
TrendMicroTROJ_GEN.R002C0OAP24
Trapminemalicious.moderate.ml.score
CMCGeneric.Win32.31a1e12c22!MD
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataApplication.Generic.7570
JiangminTrojan/FakeHotmail.a
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Spy.Gen
VaristW32/Trojan.UZPV-0587
Antiy-AVLTrojan/Win32.FakeHotmail
KingsoftWin32.Trojan.Scar.kmwr
XcitiumMalware@#1gd201czvwtxq
ArcabitApplication.Generic.D1D92
ViRobotTrojan.Win32.FakeHotmail.237311
ZoneAlarmTrojan.Win32.Scar.kmwr
MicrosoftTrojan:Win32/Sisrop!rts
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.R512016
VBA32BScope.Adware.Presenoker
ALYacApplication.Generic.7570
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0OAP24
TencentMalware.Win32.Gencirc.114e9c55
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FakeHotmail.B!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan:Win32/Sisrop!rts?

Trojan:Win32/Sisrop!rts removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment