Spy Trojan

Trojan-Spy.Win32.Windigo.vho removal tips

Malware Removal

The Trojan-Spy.Win32.Windigo.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Windigo.vho virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
g.secondmeetparty.com

How to determine Trojan-Spy.Win32.Windigo.vho?


File Info:

crc32: C16DBF5B
md5: 68fa035dc5be2c6cc98ec64f3adbce9f
name: 68FA035DC5BE2C6CC98EC64F3ADBCE9F.mlw
sha1: 6c8d5346e478ddfce14631b975757fa583262c98
sha256: 5a24479b3284cd9982959bd33b7766cd020fd69f627b8c4f990fe7e4b03e8872
sha512: a7c2399bc776abdedd7261b0922dd616198c832ed63fe3463e8a8f9a1d29258ed61ee26bf8038ab7cd5647db54cd5d062fdfb4cf022968f2afd6beb71b96ac71
ssdeep: 6144:M/OKTPJXHG4QgrhWlwzOS7fcpdbT7uGlgM8B:4TPJXHG4TNWlwzOCedbTiG6x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0147 0x00c1

Trojan-Spy.Win32.Windigo.vho also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Titirez.1.31
FireEyeGeneric.mg.68fa035dc5be2c6c
ALYacGen:Heur.Mint.Titirez.1.31
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Heur.Mint.Titirez.1.31
K7GWTrojan ( 005721291 )
K7AntiVirusTrojan ( 005721291 )
CyrenW32/Kryptik.CIX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Generickdz-9785960-0
KasperskyHEUR:Trojan-Spy.Win32.Windigo.vho
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareGen:Heur.Mint.Titirez.1.31
EmsisoftTrojan.Crypt (A)
DrWebTrojan.MulDrop15.10650
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
MaxSecureTrojan.Malware.300983.susgen
JiangminTrojanSpy.Windigo.se
MicrosoftTrojan:Win32/Wacatac.D5!ml
ArcabitTrojan.Mint.Titirez.1.31
ZoneAlarmHEUR:Trojan-Spy.Win32.Windigo.vho
GDataWin32.Trojan-Proxy.Bunitu.RSCNM1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Smokeldr.R354635
Acronissuspicious
McAfeeTrojan-FSWW!68FA035DC5BE
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Kryptik.HHCC
TencentMalware.Win32.Gencirc.11b10821
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HHGA!tr
BitDefenderThetaGen:NN.ZexaF.34634.pqW@aGbW1imG
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.6e478d
Qihoo-360HEUR/QVM20.1.455B.Malware.Gen

How to remove Trojan-Spy.Win32.Windigo.vho?

Trojan-Spy.Win32.Windigo.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment