Trojan

VHO:Trojan-Dropper.Win32.Sysn (file analysis)

Malware Removal

The VHO:Trojan-Dropper.Win32.Sysn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Dropper.Win32.Sysn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (10 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

www.baidu.com
www.bing.com
ss.bdimg.com
s1.bdstatic.com
hectorstatic.baidu.com
dj1.baidu.com
dj2.baidu.com
passport.baidu.com
eclick.baidu.com

How to determine VHO:Trojan-Dropper.Win32.Sysn?


File Info:

crc32: DE935164
md5: 99c01e2d73babd2e1a1260a7b3bddcd8
name: 99C01E2D73BABD2E1A1260A7B3BDDCD8.mlw
sha1: 57c0e6aa63d79a77c4f739fc69ed94a7e5086dbd
sha256: aead8a6d037e9a6dea2ebad18de8f8464e198ee0d5055cec423db69526d34646
sha512: d6d37d465b78bb1d16838c0ceea372f33d4cef433cc39dd9cfbd32ac839341eed33b391a25f00f6a541c3a7c3bd87157eb1434a39a2b272aa330679fdfebdafd
ssdeep: 12288:tCvYiG4XdLcqeOgeNiroSvcY38R87AZI+LtplZj2wSt27w1HDMOmwSCl:cvYi1XdLUiNDY3yG+LflM2cND9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VHO:Trojan-Dropper.Win32.Sysn also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052c8a31 )
Elasticmalicious (high confidence)
DrWebTrojan.Obfuscated.based.1
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.JP.WyW@aWO6j0p
ZillyaTrojan.Obfuscated.Win32.86584
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.d73bab
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Emotet-7645224-0
KasperskyVHO:Trojan-Dropper.Win32.Sysn.gen
BitDefenderGen:Trojan.Heur.JP.WyW@aWO6j0p
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Trojan.Heur.JP.WyW@aWO6j0p
TencentWin32.Trojan.Heur.Hwmi
Ad-AwareGen:Trojan.Heur.JP.WyW@aWO6j0p
SophosML/PE-A
ComodoMalware@#3qz42zmdmjaac
BitDefenderThetaAI:Packer.C4B508CC1E
VIPRETrojan-Dropper.Win32.Resdro.b (v) (not malicious)
McAfee-GW-EditionBehavesLike.Win32.HLLP.bc
FireEyeGeneric.mg.99c01e2d73babd2e
EmsisoftGen:Trojan.Heur.JP.WyW@aWO6j0p (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Hupigon.btkc
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tiggre!rfn
ArcabitTrojan.Heur.JP.E6F140
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Trojan.Heur.JP.WyW@aWO6j0p
Acronissuspicious
McAfeeArtemis!99C01E2D73BA
MAXmalware (ai score=98)
VBA32BScope.Trojan.Obfuscated
MalwarebytesMalware.AI.3560105561
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.100 (RDML:pSbXtNA0ErmDb4C5UVqXGQ)
YandexTrojan.GenAsa!T7n4BM1XNQw
IkarusTrojan.Obfuscated
MaxSecureTrojan.Malware.73758842.susgen
FortinetW32/Filecoder.FV!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove VHO:Trojan-Dropper.Win32.Sysn?

VHO:Trojan-Dropper.Win32.Sysn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment