Trojan

What is “Trojan-DDoS.Win32.Windigo.alv”?

Malware Removal

The Trojan-DDoS.Win32.Windigo.alv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-DDoS.Win32.Windigo.alv virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects the presence of Wine emulator via function name
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system

How to determine Trojan-DDoS.Win32.Windigo.alv?


File Info:

name: C94339DD13AA9B0106FE.mlw
path: /opt/CAPEv2/storage/binaries/7b652771f78624d3594ca3ea1ac6f65b216cd8e8415ce4cfe2bf15efbb8658d8
crc32: 8675840C
md5: c94339dd13aa9b0106feada16a54326b
sha1: 2429c9930107900d156c9821d9a4cdef5438280b
sha256: 7b652771f78624d3594ca3ea1ac6f65b216cd8e8415ce4cfe2bf15efbb8658d8
sha512: 88a298301fb4958ce59880b4686aee69d63654d2cbd7cae6cbcd578074d90c14e8f216d1f1c2c2519035c17b43b77e69b02a3d0cbd9ddf2f8c1e1de2926bc77b
ssdeep: 98304:RoLy3/M1Rl7EQmKaTnDGbRocoMXuqxiZhKhovM3f4sa1BpG1gR:ca4Rl7EQKTnDyRJuQ7hovsAruG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D936330277C6C877C93205394465DBA7A67CFE340B268AE7B7C8152C1FB81D07672AB9
sha3_384: b28385393566f647d2aab11d207b2e27db319c5dcdb8014dba9af61fad1398c58a00a5ae9859642c39bf11716247d825
ep_bytes: e886050000e98efeffffff2550a14100
timestamp: 2019-01-09 07:35:32

Version Info:

FileVersionStart: 1.0.58.4
InternalName: osfdbsvf.isi
LegalCopyright: Copyright (C) 2019, kilgiulg
ProductVersion: 51.9.1

Trojan-DDoS.Win32.Windigo.alv also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Brsecmon.1
FireEyeGeneric.mg.c94339dd13aa9b01
CAT-QuickHealRansom.Stop.MP4
McAfeeTrojan-FRJH!C94339DD13AA
CylanceUnsafe
ZillyaTool.Windigo.Win32.39
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005574c61 )
AlibabaTrojan:Win32/Windigo.b6957009
K7GWTrojan ( 005574c61 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.ADF.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GWHC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-DDoS.Win32.Windigo.alv
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Windigo.fyqdmu
AvastWin32:Trojan-gen
TencentWin32.Trojan-ddos.Windigo.Syhn
Ad-AwareTrojan.Brsecmon.1
EmsisoftTrojan.Agent (A)
ComodoMalware@#27z229xc1qg2n
DrWebTrojan.MulDrop10.49745
VIPRETrojan.Brsecmon.1
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionTrojan-FRJH!C94339DD13AA
SophosMal/Generic-R + Mal/GandCrab-G
IkarusTrojan.Win32.CryptInject
GDataTrojan.Brsecmon.1
JiangminTrojanDDoS.Windigo.pf
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1237867
Antiy-AVLTrojan/Generic.ASMalwS.50E9
MicrosoftTrojan:Win32/Skeeyah.A!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MalPe31.Suspicious.X2022
BitDefenderThetaGen:NN.ZexaF.34582.@B0@aiN9goaG
ALYacTrojan.Brsecmon.1
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@AI.92 (RDMK:ylOiDJZHqYPKTg5a1o8wWQ)
YandexTrojan.DDoS.Windigo!N7G1+2V2WoQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74547267.susgen
FortinetW32/Kryptik.GWHV!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.d13aa9
PandaTrj/GdSda.A

How to remove Trojan-DDoS.Win32.Windigo.alv?

Trojan-DDoS.Win32.Windigo.alv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment