Trojan

Win32/TrojanDropper.VB.NJL removal guide

Malware Removal

The Win32/TrojanDropper.VB.NJL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.VB.NJL virus can do?

  • Executable code extraction
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/TrojanDropper.VB.NJL?


File Info:

crc32: 698CD00D
md5: fa5e088bfaedf27c9b9a0ffdf6696afa
name: FA5E088BFAEDF27C9B9A0FFDF6696AFA.mlw
sha1: 848f350818c0fe6f912cd7f1db605e464851c685
sha256: b256c0a83252a7c1f0438e3a1bf085b2e117efbf3623656847f28e91ab277e07
sha512: 52263d5d072f98000e19ae2cca5f6a8a85cece943ba6a26efed40d7b524c5a63e0cf800c5061eaa76ff8598d45776029189e0758513a0512e728780f9916a561
ssdeep: 12288:DLG93R6Gd2seNNQGJ7dAjsVE6wpNIyDGf:DLG9BFToglpN6f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: aaa
FileVersion: 6.06.0006
CompanyName: Microsoft
ProductName: Update
ProductVersion: 6.06.0006
OriginalFilename: aaa.exe

Win32/TrojanDropper.VB.NJL also known as:

BkavW32.AIDetect.malware2
K7AntiVirusUnwanted-Program ( 004d38111 )
LionicHacktool.Win32.Agent.3!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.1678
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.Tm0@sPNoYihiy
CylanceUnsafe
ZillyaTool.Agent.Win32.8141
SangforTrojan.Win32.Agent.gen
CrowdStrikewin/malicious_confidence_100% (W)
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.bfaedf
CyrenW32/VBanti.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.VB.NJL
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Onlinegames-16
KasperskyConstructor.Win32.Agent.fx
BitDefenderGen:Trojan.Heur.Tm0@sPNoYihiy
NANO-AntivirusRiskware.Win32.Game.uwkh
MicroWorld-eScanGen:Trojan.Heur.Tm0@sPNoYihiy
TencentWin32.Trojan.Agent.Edxm
Ad-AwareGen:Trojan.Heur.Tm0@sPNoYihiy
SophosMal/Generic-R
ComodoConstructor.Win32.VB.~A@1187n
BitDefenderThetaAI:Packer.A46FE2311D
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PG121
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
FireEyeGeneric.mg.fa5e088bfaedf27c
EmsisoftGen:Trojan.Heur.Tm0@sPNoYihiy (B)
SentinelOneStatic AI – Malicious PE
JiangminConstructor.Agent.qn
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.11AAA
MicrosoftTrojan:Win32/Azorult!ml
ZoneAlarmConstructor.Win32.Agent.fx
GDataGen:Trojan.Heur.Tm0@sPNoYihiy
McAfeeGeneric Dropper.gi.gen
MAXmalware (ai score=100)
VBA32Constructor.Agent
MalwarebytesTrojan.FakeMS.ED
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PG121
YandexTrojan.GenAsa!VCSQ2a4UJzg
IkarusConstructor.Win32.Agent
MaxSecureTrojan.Malware.14964.susgen
FortinetW32/Agent.FX!kit
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/TrojanDropper.VB.NJL?

Win32/TrojanDropper.VB.NJL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment