Trojan

How to remove “Trojan:Win32/Vidar.RPY!MTB”?

Malware Removal

The Trojan:Win32/Vidar.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vidar.RPY!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Vidar.RPY!MTB?


File Info:

name: A897046EF8BFF17CAFD8.mlw
path: /opt/CAPEv2/storage/binaries/20ee492d5839a7288da875511c9449a37c8d45a0a7491b5c63a37f63d36b51c5
crc32: EB1D5E24
md5: a897046ef8bff17cafd822b19c1e532d
sha1: dd9ea6e56a8ef40b1d3fe76582806a813da04dc4
sha256: 20ee492d5839a7288da875511c9449a37c8d45a0a7491b5c63a37f63d36b51c5
sha512: 0fedb350b267b77a8edb70d0d0cb76563df6142f0e3372fdfdf17affff39e534932b779fadf0a2e19649dc76a2910c0af0e8bab9ef682ad770827f13af896ed2
ssdeep: 24576:IRu16WYdRNDl0Et8uEXE6dl5H92r5HAuNY:oVNDl0Et8uEXE6ds1HAu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D415821892306E2AC0C31FB07DBA936E41D42568E31DCEE65A7DDCB5F6EC8436D025DA
sha3_384: 7059c10279d4539abee6949bdd5598edc183f9f243d37cf3dc12ace724980905f1e494c1352b969b9196aa009ad4c65a
ep_bytes: f6460c408b06740938187407408906eb
timestamp: 2023-07-24 09:51:12

Version Info:

0: [No Data]

Trojan:Win32/Vidar.RPY!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.327189
FireEyeGeneric.mg.a897046ef8bff17c
SkyhighBehavesLike.Win32.Generic.cm
McAfeeArtemis!A897046EF8BF
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Fragtor.327189
K7AntiVirusPassword-Stealer ( 005948581 )
BitDefenderGen:Variant.Fragtor.327189
K7GWPassword-Stealer ( 005948581 )
Cybereasonmalicious.56a8ef
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Vidar.A
APEXMalicious
KasperskyTrojan-PSW.Win32.Vidar.cvg
RisingTrojan.Generic@AI.100 (RDML:P+ZVujWrIa7IOqTBwGU1Mw)
SophosGeneric ML PUA (PUA)
ZillyaTrojan.Agent.Win32.3621235
EmsisoftGen:Variant.Fragtor.327189 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
GoogleDetected
VaristW32/Agent.GHQ.gen!Eldorado
Antiy-AVLTrojan[PSW]/Win32.Convagent
Kingsoftmalware.kb.a.989
MicrosoftTrojan:Win32/Vidar.RPY!MTB
ArcabitTrojan.Fragtor.D4FE15
ZoneAlarmTrojan-PSW.Win32.Vidar.cvg
GDataGen:Variant.Fragtor.327189
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.36792.1qZ@aaoqhWo
ALYacGen:Variant.Fragtor.327189
TACHYONTrojan-PWS/W32.Vidar.880640.B
DeepInstinctMALICIOUS
Cylanceunsafe
TencentMalware.Win32.Gencirc.10bf0f6d
IkarusTrojan-PSW.Agent
MaxSecureTrojan.Malware.215142197.susgen
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Vidar.RPY!MTB?

Trojan:Win32/Vidar.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment