Virus

Virus:Win32/Tref.A malicious file

Malware Removal

The Virus:Win32/Tref.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Tref.A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Virus:Win32/Tref.A?


File Info:

name: 465119DF575691C776BF.mlw
path: /opt/CAPEv2/storage/binaries/e45c34bc57569bbb37f0f7cc19747730e1240150f1f9192eab665ab7fbd697ee
crc32: B19EB2B1
md5: 465119df575691c776bfedefb57e3a67
sha1: 750dbc02d53fdabec291310208550790bdf6ef38
sha256: e45c34bc57569bbb37f0f7cc19747730e1240150f1f9192eab665ab7fbd697ee
sha512: 8618024696074a12845e7f66fa14625adc3b63b832382d49d8e2a7cc8b654be8ecb3adf6b7f574e299d9bf66f47d3cdc74692a55dff84f676a66f8b0349ca574
ssdeep: 3072:e+tBkxyxLSl74xVhohYkQr0jeLwJr95rJoW:HkGLQoiYQqLwhHrW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131F3AD4BF6B089B1D0A04AB88C25E785AD7A7D305E708147B6AD3E8F3F752C2985C357
sha3_384: 93f6fac0a6b38a976fb65b1c7169202c83ab3cf10728e6d9263e4fc188ee72490e09c84804da9aa6a94b7c4b74a5286f
ep_bytes: 558becb9280000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Virus:Win32/Tref.A also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Tref.n!c
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Tref
MicroWorld-eScanGen:Trojan.Heur.jGZ@Hvf7kVg
ClamAVWin.Trojan.Tref-1
FireEyeGeneric.mg.465119df575691c7
ALYacGen:Trojan.Heur.jGZ@Hvf7kVg
MalwarebytesMalware.AI.275251838
VIPREGen:Trojan.Heur.jGZ@Hvf7kVg
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001140e1 )
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.f57569
BitDefenderThetaAI:Packer.AD75A57A1B
CyrenW32/Risk.WYBZ-2527
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Tref.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Tref.a
BitDefenderGen:Trojan.Heur.jGZ@Hvf7kVg
NANO-AntivirusTrojan.Win32.HLLP.egsfg
AvastWin32:Evo-gen [Trj]
TencentWin32.Virus.Tref.Qsmw
EmsisoftGen:Trojan.Heur.jGZ@Hvf7kVg (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
ZillyaBackdoor.Krap.Win32.4037
TrendMicroVirus.Win32.TREF.A
McAfee-GW-EditionBehavesLike.Win32.Virus.ch
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.jGZ@Hvf7kVg
JiangminWin32/Tref.a
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan/Win32.Tref.a
XcitiumTrojWare.Win32.TrojanDownloader.Small.T@128mxy
ArcabitTrojan.Heur.E96CD8
ZoneAlarmVirus.Win32.Tref.a
MicrosoftVirus:Win32/Tref.A
GoogleDetected
McAfeeArtemis!465119DF5756
MAXmalware (ai score=80)
VBA32Win32.Trojan.Dropper.Heur
Cylanceunsafe
RisingMalware.Undefined!8.C (TFE:4:o9M2E6OLAZR)
YandexTrojan.ATRAPS!BFDT7P46vvo
IkarusVirus.Win32.Tref
MaxSecureVirus.W32.Tref.A
FortinetW32/Tref.A
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Tref.A?

Virus:Win32/Tref.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment