Trojan

Trojan-Proxy.Win32.Windigo.eav malicious file

Malware Removal

The Trojan-Proxy.Win32.Windigo.eav is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Proxy.Win32.Windigo.eav virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Proxy.Win32.Windigo.eav?


File Info:

name: FE13DDE565217BD24186.mlw
path: /opt/CAPEv2/storage/binaries/d1d8cb0611ada08401a94de8c46c2217519f0bc42cba0a5a04511b6db7b81707
crc32: D43ABE2F
md5: fe13dde565217bd24186cf09d9b3c073
sha1: 00884a48703ecdd0924e52a3e67474e7221ffe7c
sha256: d1d8cb0611ada08401a94de8c46c2217519f0bc42cba0a5a04511b6db7b81707
sha512: 30da2d927ab4d0e973636f260d635639a4997f0fabf5bb851cc02fde51d13d814dc91d555cae02235d374dce45b081a24f4a06bd8705ba7ac16f7dc27ffacd32
ssdeep: 98304:6dIl6d0Z5xU6yac+hgQugZmSVPrH7Hj1a2gVn1YA8LmxFOrz2u166qVO37Nr1/CW:mIXZ5xPcG8MHVPrbHa1Yb8FTW66qor+W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5363348F475677AF8390DBE4C874A3203177E573C3A5972459EAC88036B7208DA87BE
sha3_384: 64286305e9f46eb3870deeb31ed1b9b3ed799ffba1bcbbc07e88e66fe9b9611f4ad8190507e336b341ff6b31b342b0cf
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 2023-11-05 00:36:43

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: DBuster Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan-Proxy.Win32.Windigo.eav also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Windigo.h!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
MalwarebytesTrojan.Dropper
SangforHacktool.Win32.Windigo.Vb61
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan-Proxy.Win32.Windigo.eav
AlibabaTrojan:Win32/Windigo.340cfc91
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1332256
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Injuke.sus
AviraHEUR/AGEN.1332256
MicrosoftTrojan:Win32/ICLoader.JL!MTB
ZoneAlarmTrojan-Proxy.Win32.Windigo.eav
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R620756
McAfeeArtemis!FE13DDE56521
DeepInstinctMALICIOUS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CK523
TencentWin32.Trojan-Proxy.Windigo.Rimw
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
AvastOther:Malware-gen [Trj]

How to remove Trojan-Proxy.Win32.Windigo.eav?

Trojan-Proxy.Win32.Windigo.eav removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment