Threat Database Trojans Trojan.Vidar.F

Trojan.Vidar.F

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 3,626
Threat Level: 80 % (High)
Infected Computers: 3,195
First Seen: September 4, 2023
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Vidar.F on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Vidar.F?

Trojan.Vidar.F is a detected threat that falls under the category of Trojans, which are malicious programs designed to gain unauthorized access to a computer system. The name itself does not specify a particular malware family, but rather indicates that it has been identified as a Trojan-type threat. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access to the infected system.

How Trojan.Vidar.F Operates

Like other Trojans, Trojan.Vidar.F is likely designed to operate stealthily, attempting to evade detection by security software. It may use various techniques to infect a system, such as exploiting vulnerabilities in software, disguising itself as a legitimate program, or being downloaded inadvertently by a user. Once installed, it can start executing its payload, which could range from data theft to malware installation, depending on its intended purpose.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely, depending on the specific actions of the malware. Common indicators include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs running in the background. You might also notice changes in your browser settings, unexpected pop-ups, or suspicious network activity. However, some Trojans are designed to be silent and may not exhibit any noticeable symptoms, making regular system scans crucial for detection.

How to Remove Trojan.Vidar.F

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the Trojan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time of the infection. Be cautious and only remove programs you are certain are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that all traces of the Trojan have been removed.

Conclusion

Removing Trojan.Vidar.F requires a combination of technical knowledge and the right tools. It's crucial to act quickly to prevent further damage and protect your personal data. Regularly updating your operating system, using reputable security software, and practicing safe computing habits can significantly reduce the risk of future infections. Remember, vigilance and proactive measures are key to maintaining the security and integrity of your computer system.

Analysis Report

General information

Family Name: Trojan.Vidar.F
Signature status: Hash Mismatch

Known Samples

MD5: e0b0dd8db59f25288937c7223d074213
SHA1: f6b4981946ab8aaf43ba2c375aa271af0c0f4f5f
SHA256: EEF3C3C7BA7227258454A2C46F56C5766F6585A92B12A488BEB6D2CF1754E6D4
File Size: 6.48 MB, 6477312 bytes
MD5: 805b0c04bf68954efcf77bb1b7ffb8e7
SHA1: eba565e7757d5d580de539056bfe83e48766bc87
SHA256: 9EE5976C70184734292F5B542DEA452986520D44E9462FF4F2AB7DAF5FFDE11E
File Size: 4.49 MB, 4494565 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name VMware, Inc.
File Description VMware base library
File Version 16.1.0 build-17198959
Internal Name vmwarebase
Legal Copyright Copyright © 1998-2020 VMware, Inc.
Original Filename vmwarebase.dll
Product Name VMware Workstation
Product Version 16.1.0 build-17198959

Digital Signatures

Signer Root Status
ASUSTeK Computer Inc. DigiCert SHA2 High Assurance Code Signing CA Hash Mismatch

File Traits

  • 2+ executable sections
  • CryptUnprotectData
  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 1,240
Potentially Malicious Blocks: 39
Whitelisted Blocks: 917
Unknown Blocks: 284

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? x x ? x ? ? ? 0 0 ? ? x x x x ? ? x x x x x ? ? x x ? ? x x x 0 ? ? x x ? x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 3 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 2 1 0 1 0 0 1 1 1 0 1 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x ? ? ? 0 0 ? ? ? 0 0 ? 0 ? ? ? ? x ? 0 ? ? 0 x 0 ? ? ? ? ? 0 ? ? 0 0 0 ? 0 0 ? ? ? ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 x ? ? ? 0 ? x ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? x ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 ? 0 ? ? ? x 0 ? 0 ? ? ? ? ? 0 0 ? x ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? x ? ? 0 0 ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f6b4981946ab8aaf43ba2c375aa271af0c0f4f5f_0006477312.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\eba565e7757d5d580de539056bfe83e48766bc87_0004494565.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...