Trojan

Trojan:Win32/Vindor!atmnm information

Malware Removal

The Trojan:Win32/Vindor!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vindor!atmnm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Vindor!atmnm?


File Info:

name: F3EB7377B454FD731836.mlw
path: /opt/CAPEv2/storage/binaries/faf21bf3bd28374be125c0762b7fa7190071b07ab6c3c28d833e77107f4dc805
crc32: E52A4B6F
md5: f3eb7377b454fd731836beaf701384de
sha1: 554b97ae6fa1ca59929e296a7b9c340a76009ba8
sha256: faf21bf3bd28374be125c0762b7fa7190071b07ab6c3c28d833e77107f4dc805
sha512: e3be3e71a9ed2c5351c4dd3ff0676c253c6c35f32dc8ca1796216f097ad036890dc3b38c1ea8ccd2e14696c46d41bee82ed11bcf3fe0cb7cb1ea44a96837d8ff
ssdeep: 3072:cEdOQzZnx6OJPa0UVKS1DNB4jQVckmFP5GTBiRw0OZ9pB05OZalrl7Sy+uwY4d:hzZnx68OKSOjQ7m+TUWzpm5aSxTXw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1241225B55E56EAC03E0B381C7BD3521019D7596B2252B7BA0C579E2FCA1034FA33BE
sha3_384: bacc6709569bd292a473abbdeb165acb3f34c4767fa0b16cbc908e89cfd220e421e3d9272b6d5ad1d6c8b3a572bd27d8
ep_bytes: 558bec83ec585756ff75dcff75cc8d15
timestamp: 2003-09-12 13:51:34

Version Info:

FileDescription: ZoneAlarm Stub Program for ZAPro
LegalCopyright: Copyright © 1998-2010, Check Point, LTD
InternalName: zonestub
ProductName: ZoneAlarm Pro
CompanyName: Check Point Software Technologies LTD
FileVersion: 4.8.5.8
ProductVersion: 5.7.9.3
Translation: 0x0409 0x0000

Trojan:Win32/Vindor!atmnm also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.104050
FireEyeGeneric.mg.f3eb7377b454fd73
SkyhighBehavesLike.Win32.PWSZbot.dc
McAfeeGeneric BackDoor.acx
Cylanceunsafe
ZillyaBackdoor.Shiz.Win32.1006
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e6fa1c
VirITBackdoor.Win32.Generic.NBD
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.SLJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-316241
KasperskyBackdoor.Win32.Shiz.hmu
BitDefenderTrojan.GenericKDZ.104050
NANO-AntivirusTrojan.Win32.Shiz.eally
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
AvastWin32:Downloader-IWM [Trj]
TencentMalware.Win32.Gencirc.10bf3663
TACHYONBackdoor/W32.Shiz.214528.B
SophosMal/FakeAv-NL
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Packed.20771
VIPRETrojan.GenericKDZ.104050
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.104050 (B)
IkarusTrojan-PWS.Win32.Simda
JiangminBackdoor/Shiz.aux
VaristW32/Kryptik.KXJ.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Shiz
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Vindor!atmnm
ArcabitTrojan.Generic.D19672
ViRobotBackdoor.Win32.A.Shiz.61697
ZoneAlarmBackdoor.Win32.Shiz.hmu
GDataWin32.Trojan.Agent.EJGJA4
GoogleDetected
AhnLab-V3Trojan/Win.Injector.R621185
BitDefenderThetaGen:NN.ZexaF.36792.nO0@a0Ov@Jmi
ALYacTrojan.GenericKDZ.104050
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Coins
MalwarebytesMalware.AI.4227003501
PandaTrj/Genetic.gen
RisingTrojan.Vindor!8.10CC (TFE:1:IZv9EZUclEG)
YandexBackdoor.Shiz!xNacylONRKQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Shiz.F!tr.bdr
AVGWin32:Downloader-IWM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Vindor!atmnm?

Trojan:Win32/Vindor!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment