Virus

Virus:Win32/Detroie.A removal guide

Malware Removal

The Virus:Win32/Detroie.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Detroie.A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Detroie.A?


File Info:

name: A978137EC42812BB1AFB.mlw
path: /opt/CAPEv2/storage/binaries/0441171968ea4c7a4ac60dc459ea33a5ba1558cf3a70b043cc68f89363ce282b
crc32: DAFAAF08
md5: a978137ec42812bb1afb9597b05de715
sha1: 60daf2cc22ba60cef67c59dda97484054950c8b4
sha256: 0441171968ea4c7a4ac60dc459ea33a5ba1558cf3a70b043cc68f89363ce282b
sha512: ccaf77c90358216b5c84eadd51286cba51a0862f26ed154d072d72d37f5d261ab82ddc72f4767599e7e990f7e3a23e15b04eb8f2c5a4a6970d5fd2384d025458
ssdeep: 12288:5pQN/7w3W2uyQOxwiAhZCgLPdlSS8pXTxwl:5iNz+/93xMi4nSS8p1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14AC45D27F2908833D1721A388D5B97A89C26BE503E38DC4B77F91E4C5E7978179262D3
sha3_384: 73925b27b80aae08513fa346b6f52057ba363d36a7aa68846ead2c02f2fba78d355ab99d32cd142b7515c08b6830254e
ep_bytes: 558bec83c4f4b808a04500e8fcb7faff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Virus:Win32/Detroie.A also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.HLLP.DeTroie.C
CAT-QuickHealHLLP.DeTroie
SkyhighBehavesLike.Win32.Generic.hm
McAfeeW32/Cheval.b.dr
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.DeTroie.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00597a181 )
K7GWTrojan ( 00597a181 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.HLLP.DeTroie
tehtrisGeneric.Malware
ESET-NOD32Win32/HLLP.DeTroie
APEXMalicious
TrendMicro-HouseCallPE_HLLPDeTroie
ClamAVWin.Trojan.DeTroie-1
KasperskyVirus.Win32.HLLP.DeTroie
BitDefenderWin32.HLLP.DeTroie.C
NANO-AntivirusTrojan.Win32.DetroiA.bbraai
AvastWin32:Cheval
TencentVirus.Win32.Hllp.aab
SophosW32/Cheval-B
F-SecureTrojan.TR/DetroiA.Gen
DrWebWin32.HLLP.Cheval
VIPREWin32.HLLP.DeTroie.C
TrendMicroPE_HLLPDeTroie
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.a978137ec42812bb
EmsisoftWin32.HLLP.DeTroie.C (B)
IkarusVirus.Win32.HLLP.DeTroie
JiangminWin32/HLLP.DeTroie
GoogleDetected
AviraTR/DetroiA.Gen
VaristW32/HLLP.DeTroie.A
Antiy-AVLVirus/Win32.HLLP.detroie
MicrosoftVirus:Win32/Detroie.A
XcitiumVirus.Win32.HLLP.DeTroie.E@n97ec
ArcabitWin32.HLLP.DeTroie.C
ViRobotWin32.DeTroie
ZoneAlarmVirus.Win32.HLLP.DeTroie
GDataWin32.HLLP.DeTroie.C
CynetMalicious (score: 100)
AhnLab-V3Win32/HLLP.Detroie
VBA32Win32.HLLP.DeTroie
MAXmalware (ai score=89)
Cylanceunsafe
ZonerProbably Heur.ExeHeaderP
RisingWorm.Cheval!1.A14A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Win32.HLLP.DeTroie
FortinetW32/DeTroie.E
BitDefenderThetaGen:NN.ZelphiF.36802.JO3@amx5Flke
AVGWin32:Cheval
Cybereasonmalicious.ec4281
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Detroie.HWPJ

How to remove Virus:Win32/Detroie.A?

Virus:Win32/Detroie.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment