Spy Trojan

Trojan-Spy.Win32.Stealer.vho (file analysis)

Malware Removal

The Trojan-Spy.Win32.Stealer.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.vho virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.vho?


File Info:

crc32: 062E1E0E
md5: 3a7d2f1815f84f8f678af316d2475e34
name: 3A7D2F1815F84F8F678AF316D2475E34.mlw
sha1: f13b3cfee8d1f65583a9dd7fc98362e105f19d8e
sha256: 848d04f917e919caaf01ce7d1210a92c8516f1df5832d7a78d72f9c3b9aa4973
sha512: df1cd6b0423594b5b0794e6505dc858cd77b66aa10b5a810d780c1ae16ad000aa85045171b464f4deef4e2783b8c824c48208ba000fa3b3d18f4b57030530eb2
ssdeep: 3072:DDKW1LgppLRHMY0TBfJvjcTp5XOEz5bEZRgtT57cIw4ed0ZfEe2+:DDKW1Lgbdl0TBBvjc/OZUw4E0fX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Reamers.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Reamers.exe

Trojan-Spy.Win32.Stealer.vho also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Dopping.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Trojan.DAN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DCX
APEXMalicious
AvastWin32:MdeClass
KasperskyHEUR:Trojan-Spy.Win32.Stealer.vho
BitDefenderGen:Variant.Dopping.1
SUPERAntiSpywareTrojan.Agent/Gen-MSIL
MicroWorld-eScanGen:Variant.Dopping.1
Ad-AwareGen:Variant.Dopping.1
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34628.mq0@aWtXYhp
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.3a7d2f1815f84f8f
EmsisoftGen:Variant.Dopping.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1139343
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/ClipBanker.MR!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.vho
GDataGen:Variant.Dopping.1
Acronissuspicious
MAXmalware (ai score=84)
MalwarebytesTrojan.Crypt.MSIL.Generic
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrad6q650dUlRTYgX0pNyvA)
IkarusTrojan.MSIL.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:MdeClass
Qihoo-360HEUR/QVM10.1.1215.Malware.Gen

How to remove Trojan-Spy.Win32.Stealer.vho?

Trojan-Spy.Win32.Stealer.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment