Trojan

Trojan:Win32/Veslorn!A removal tips

Malware Removal

The Trojan:Win32/Veslorn!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Veslorn!A virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Veslorn!A?


File Info:

crc32: 5B9D6374
md5: 3a4c6a7c174691b747b22abeebe6be21
name: 3A4C6A7C174691B747B22ABEEBE6BE21.mlw
sha1: 416ce6a7a2d5d84199eff439dc4c83e7f67bbfa0
sha256: 7e8fe05586b74995acbf4456cab75cb51cdab53e6cc567f5db5f88a88a6ddd72
sha512: d2945edfc2f330aa48a549e5dfa1d6737874a9f976c54ae1da2430324bee570bc20227df086c5ac5a150bd3a073b6372374465e17f379fa4904f234dbacf666e
ssdeep: 768:m/U71z02mfeXxsmlNqhCPBlDWQenbcuyD7UKf:1V02P9NqhKbD9enouy8Kf
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName:
FileVersion:
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName:
SpecialBuild:
ProductVersion:
FileDescription:
OriginalFilename:
Translation: 0x0804 0x04b0

Trojan:Win32/Veslorn!A also known as:

K7AntiVirusTrojan ( 004cc7e21 )
LionicTrojan.Win32.Ceckno.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Rincux.AW
CMCGeneric.Win32.3a4c6a7c17!CMCRadar
ALYacTrojan.Rincux.AW
CylanceUnsafe
ZillyaTrojan.Ceckno.Win32.143
SangforTrojan.Win32.Veslorn.gen
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Veslorn.04a193ae
K7GWTrojan ( 004cc7e21 )
Cybereasonmalicious.c17469
CyrenW32/Downloader.I.gen!Eldorado
SymantecBackdoor.Trojan
ESET-NOD32Win32/Ceckno.DL
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.g
BitDefenderTrojan.Rincux.AW
NANO-AntivirusTrojan.Win32.Krap.devjxr
TencentWin32.Packed.Krap.Lkee
Ad-AwareTrojan.Rincux.AW
SophosMal/Behav-010
ComodoBackdoor@#2d7h023btrduz
DrWebBackDoor.Attack.22
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_VESLORN.EE
McAfee-GW-Editiongeneric!bg.esp
FireEyeGeneric.mg.3a4c6a7c174691b7
EmsisoftTrojan.Rincux.AW (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Ceckno.ach
WebrootW32.Malware.Gen
AviraTR/Downloader.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1026AC7
KingsoftWin32.Troj.Krap.g.(kcloud)
MicrosoftTrojan:Win32/Veslorn.gen!A
SUPERAntiSpywareTrojan.Agent/Gen-Peed
ZoneAlarmPacked.Win32.Krap.g
GDataTrojan.Rincux.AW
AhnLab-V3Packed/Win32.Krap.C137513
Acronissuspicious
McAfeegeneric!bg.esp
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Attack
PandaBck/Ceckno.H
TrendMicro-HouseCallTROJ_VESLORN.EE
RisingBackdoor.Agent!1.6628 (CLASSIC)
YandexTrojan.GenAsa!+KtR5pr/yGk
IkarusBackdoor.Win32.Ceckno
MaxSecureTrojan.Malware.749424.susgen
FortinetW32/CoinMiner.BELF!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan:Win32/Veslorn!A?

Trojan:Win32/Veslorn!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment