Threat Database Trojans Trojan.VMDetector.A

Trojan.VMDetector.A

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 180
First Seen: September 1, 2021
Last Seen: February 10, 2026
OS(es) Affected: Windows

The detection of Trojan.VMDetector.A on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise the integrity of your computer and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.VMDetector.A?

Trojan.VMDetector.A is a type of malicious software that can infiltrate your computer without your knowledge or consent. The name itself suggests that it may be related to virtual machine detection, but the exact nature and purpose of this threat are not immediately clear. What is certain, however, is that it poses a significant risk to your system's security and your personal data. Trojans are known for their ability to disguise themselves as legitimate programs, making them difficult to detect and remove.

How Trojan.VMDetector.A Operates

Once installed on your system, Trojan.VMDetector.A can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials, credit card numbers, or personal data. It could also install additional malware, create backdoors for remote access, or disrupt system operations. The lack of specific information about this threat makes it challenging to predict its exact behavior, but its presence is a clear indication of a security breach.

Symptoms of Infection

The symptoms of a Trojan.VMDetector.A infection can vary, but common indicators include slow system performance, unexpected crashes, and unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups and alerts. In some cases, the threat may remain dormant, waiting for specific conditions to activate its malicious payload. If you suspect that your system is infected, it is crucial to take immediate action to mitigate the damage.

How to Remove Trojan.VMDetector.A

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another scan to ensure that the threat has been completely removed.

It is essential to note that removing Trojan.VMDetector.A requires patience and caution. You may need to repeat the removal process several times to ensure that all malicious components have been eliminated.

Conclusion

The detection of Trojan.VMDetector.A is a serious security alert that requires immediate attention. By understanding the nature of this threat and following the removal steps outlined above, you can help protect your system and personal data from further compromise. Remember to always use reputable anti-malware tools, keep your operating system and software up to date, and practice safe browsing habits to minimize the risk of future infections. If you are unsure about any aspect of the removal process, consider seeking guidance from a qualified security professional to ensure the complete and safe removal of the threat.

Analysis Report

General information

Family Name: Trojan.VMDetector.A
Signature status: No Signature

Known Samples

MD5: adfe6a9cb1505936c10a420290e17cea
SHA1: 2c57f56705e49472893be48c57b2ff00f49e9e27
SHA256: 9D9B4844EBA67DD184BC2D32F82778554861E6F6CCA231BF96A8FE262D36D790
File Size: 750.59 KB, 750592 bytes
MD5: 1aee0385397ecfa0d662cd6981921da9
SHA1: 6e3b2017180d29356e1a1d85a99a75c4f1df92bf
SHA256: 3C2DC771758EF8BA07B5C0FE8022CA4D303D276027CD17B14BC35C5D1906E72C
File Size: 369.05 KB, 369047 bytes
MD5: d56577031921e047b0cdaea61f9298e5
SHA1: b761f912e0ec556d8e22679bb1b938e6c953344d
SHA256: 02E9ED2221BAA31FD3B7A0FFFDCDBD616401398857494D4CD22CA950FB5E135E
File Size: 457.20 KB, 457204 bytes
MD5: d08d8dfdc5a0da4e8bb9505762720785
SHA1: e6729c250d98be14871c2c55734b66333686f1d3
SHA256: 1CEA9C144AACC6341C754B09064CE75D715F6A5414F8596EA4B3F9CF6292D7FE
File Size: 787.97 KB, 787968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Lyrics
  • Mein Gutscheincode GmbH
File Description
  • Allyrics-1 Installer
  • Mein Gutscheincode Installer
File Version
  • 1.28.153.3
  • 1.28.153.1
Legal Copyright
  • Copyright Lyrics
  • Copyright Mein Gutscheincode GmbH
Product Name
  • Allyrics-1
  • Mein Gutscheincode

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 1,307
Potentially Malicious Blocks: 89
Whitelisted Blocks: 1,137
Unknown Blocks: 81

Visual Map

0 0 0 0 0 0 0 0 0 x 0 ? x 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 1 0 ? ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 x x x x x ? x 0 x ? ? ? ? ? x ? x 0 0 0 ? ? 0 0 ? x x x x x x x x x x ? x x ? x x x x x ? ? x ? ? x x x ? ? ? x x ? ? ? ? ? ? x x ? ? ? ? ? 0 ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 1 1 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? ? ? ? ? ? ? ? 1 0 1 x x ? x x x x ? ? ? ? ? ? ? x ? x x x x 0 0 0 x x 0 0 0 0 0 ? ? 0 x ? x x ? ? ? 0 0 0 ? ? x ? x x x x ? x x 0 0 ? x ? ? x ? ? ? x 0 0 0 0 x x x x x x ? x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 2 0 3 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 1 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\allyrics-1uninstaller_1759242272.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\allyrics-1uninstaller_1759242272.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa3942.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsa4beb.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\installerutils.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\installerutils.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\nsislog.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\nsislog.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\nsisos.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\nsisos.dll Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\nsa4beb.tmp\stdutils.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\stdutils.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\system.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\userinfo.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa4beb.tmp\userinfo.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsf4b1f.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsl4bdb.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsp372f.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsq3953.tmp\nsislog.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq3953.tmp\stdutils.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Qxgnvyjg\AppData\Local\Temp\~nsu.tmp\Au_.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Qxgnvyjg\AppData\Local\Temp\~nsu.tmp\Au_.exe\??\C:\Users\Qxgnvyjg\AppData\Local\Temp\~nsu.tmp RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Qxgnvyjg\AppData\Local\Temp\~nsu.tmp\Au_.exe\??\C:\Users\Qxgnvyjg\AppData\Local\Temp\~nsu.tmp\??\C:\Users\Qxgnv RegNtPreCreateKey
Show More
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Jk*tX �vT�����(�(X�*J*�h1�1HO@V�G�IH[u_�zb"hj�bk�qq�Xw�n{b��P��jI�/�����b:�������X�����.���a ��*�m�Ù�����$�8წ���&M��=�S/�.SLB1_T�Vw�`�V��%�������AE�Q]��D�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Kk*tX �vT�����(�(X�*J*�h1�1HO@V�G�IH[u_�zb"hj�bk�qq�Xw�n{b��P��jI�/�����b:�������X�����.���a ��*�m�Ù�����$�8წ���&M��=�S/�.SLB1_T�Vw�`�V�R���%�������AE�Q]�� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2c57f56705e49472893be48c57b2ff00f49e9e27_0000750592.,LiQMAxHB
"C:\Users\Qxgnvyjg\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"C:\Users\Hezkzrlh\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e6729c250d98be14871c2c55734b66333686f1d3_0000787968.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...