Malware

About “Win32:Immirat-A [Trj]” infection

Malware Removal

The Win32:Immirat-A [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Immirat-A [Trj] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Attempts to remove evidence of file being downloaded from the Internet
  • Sniffs keystrokes

Related domains:

dnstrafficexchange.duckdns.org

How to determine Win32:Immirat-A [Trj]?


File Info:

crc32: EF83023C
md5: 9e50b249c984b02ffe52d469a05396f2
name: vbc.exe
sha1: 5cc5ebd1ea59c61910e3672bad25ef2bba79e474
sha256: 5e106d7b95627d982862e8d97f9b057632427008df0b994cd4b99e17c41a4c26
sha512: 8c8533699f010e266b9284315a60ad8b806d6f6e331198fc492364a8dca7e87007529885d6eb986328c84498383fcc6f4e76c4376e466c37e3e46c0fb5bfbc0f
ssdeep: 6144:+Y6yVbWCcK0f1pmGZt8Y3ACX7v9Rs/RFLoC:+Y6y1W00NEU8f8v9m9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2013
Assembly Version: 1.0.0.0
InternalName: 1.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
Comments: Description
ProductName: ClientProduct
ProductVersion: 1.0.0.0
FileDescription: Client
OriginalFilename: 1.exe

Win32:Immirat-A [Trj] also known as:

MicroWorld-eScanGeneric.MSIL.PasswordStealerA.BE823801
FireEyeGeneric.mg.9e50b249c984b02f
CAT-QuickHealHackTool.Boilod.AP3
ALYacBackdoor.MSIL.Boilod
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.PasswordStealerA.BE823801
K7GWTrojan ( 700000121 )
Cybereasonmalicious.9c984b
TrendMicroBKDR_BLADABINDI.SM
BitDefenderThetaGen:NN.ZemsilF.34104.wm0@aKzJO5d
CyrenW32/MSIL_Troj.L.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataMSIL.Backdoor.Imminent.A
AlibabaBackdoor:MSIL/Boilod.a4271097
NANO-AntivirusTrojan.Win32.Agent.edcvtj
ViRobotTrojan.Win32.Z.Immirat.364032.A
Ad-AwareGeneric.MSIL.PasswordStealerA.BE823801
ComodoMalware@#17bf30utnxn5u
MaxSecureTrojan.Malware.7164915.susgen
DrWebTrojan.KeyLogger.28086
ZillyaTrojan.Immirat.Win32.482
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftGeneric.MSIL.PasswordStealerA.BE823801 (B)
IkarusTrojan.MSIL.Injector
F-ProtW32/MSIL_Troj.L.gen!Eldorado
JiangminTrojan/Generic.bhigo
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitGeneric.MSIL.PasswordStealerA.BEDC91F9
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Dynamer.R136503
MAXmalware (ai score=85)
MalwarebytesBackdoor.Agent.IMN
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Immirat.B
TrendMicro-HouseCallBKDR_BLADABINDI.SM
TencentWin32.Trojan.Generic.Hvsq
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Immirat.B!tr
AVGWin32:Immirat-A [Trj]
AvastWin32:Immirat-A [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.IM.321

How to remove Win32:Immirat-A [Trj]?

Win32:Immirat-A [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment