Malware

Win32:DangerousSig [Trj] (file analysis)

Malware Removal

The Win32:DangerousSig [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:DangerousSig [Trj] virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32:DangerousSig [Trj]?


File Info:

crc32: A97FA6A0
md5: 526ac6eabc862493d32ab7a92408c600
name: hrd777.exe
sha1: 1999462a153b91613447b9fbc28265e458c09a68
sha256: 504ac8bba3e7d8921e67031c45953f00f36ed9569834b557170c55732a457027
sha512: fda124b7b0ccba519e043489b45ae3ad3d56f29259bc8251ca932f5bb330a31f3751f29afdb46a5e640b3377132180d4cb4315d436f76a127498bad4ad009c47
ssdeep: 49152:ntaCSOBJAmcVl+Igp/1FfQzvAVV6KR85E9Tir9BwKtmcVe86qU9Qi/VNYdLYSZKI:ntaArKQdoAVPR8lwKtmcJ619fdNYdLjz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ZJFWIVCNUC
FileVersion: 1.2.8.1
CompanyName: ZJFWIVCNUC
LegalTrademarks: ZJFWIVCNUC
Comments: ZJFWIVCNUC
ProductName: ZJFWIVCNUCZJFWIVCNUC
FileDescription: ZJFWIVCNUC
Translation: 0x0409 0x04e4

Win32:DangerousSig [Trj] also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.41796819
CAT-QuickHealTrojan.Scrami
McAfeeArtemis!526AC6EABC86
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Scrami.4!c
SangforMalware
K7AntiVirusTrojan ( 00552cd01 )
BitDefenderTrojan.GenericKD.41796819
K7GWTrojan ( 00552cd01 )
Invinceaheuristic
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Delf.BJJ
TrendMicro-HouseCallTROJ_GEN.R011C0GJ219
Paloaltogeneric.ml
GDataTrojan.GenericKD.41796819
KasperskyHEUR:Trojan.Win32.Scrami.gen
AlibabaTrojan:Win32/Scrami.a01b7396
APEXMalicious
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
Ad-AwareTrojan.GenericKD.41796819
SophosMal/Generic-S
ComodoMalware@#1zg78jz5ywy5p
F-SecureHeuristic.HEUR/AGEN.1042347
DrWebPowerShell.MulDrop.75
ZillyaTrojan.Delf.Win32.115001
TrendMicroTROJ_GEN.R011C0GJ219
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.41796819
EmsisoftAdware.Agent (A)
CyrenW32/Trojan.RGGL-8384
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1042347
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D27DC4D3
AhnLab-V3PUP/Win32.RL_Generic.R278935
ZoneAlarmHEUR:Trojan.Win32.Scrami.gen
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
VBA32Trojan.Scrami
ALYacTrojan.Agent.Scrami
MalwarebytesTrojan.Dropper.PS
PandaTrj/CI.A
MaxSecureTrojan.Malware.73962854.susgen
FortinetW32/RA.NIZ!tr
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
Qihoo-360Win32/Trojan.02c

How to remove Win32:DangerousSig [Trj]?

Win32:DangerousSig [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment