Trojan

Trojan.Win32.Alien.vho malicious file

Malware Removal

The Trojan.Win32.Alien.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Alien.vho virus can do?

  • Presents an Authenticode digital signature
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

yzqdkrUJivQVOypdN.yzqdkrUJivQVOypdN

How to determine Trojan.Win32.Alien.vho?


File Info:

crc32: 9B320F44
md5: c20ef4961ce6eb9dd5654242ec1b418c
name: untill.exe
sha1: 076cb25979115c1a5baa95807f993c90f629c524
sha256: 80199402b66d52742db427b0a59c869d3629e2b503c8e84b0d17789db414c352
sha512: e518cd58bcab49e1359d6e60fe71a12c40d6c3f3e8dcfbf974848edb901231b8bd70271fc64f55c0cd8777e975ffee08b17607e4c4bd9744a4193b2a5739a9a2
ssdeep: 24576:ZQqPByJzhAfD7MjzlR7m8Sdu3ar3kxggWq:ZQqZ0z0MjHy8mxrgl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Of The Software
InternalName: Of The
FileVersion: 8.99.5763
CompanyName: Of The Software
LegalTrademarks: Of The Software
Comments: Of The Software
ProductName: Of The Software
ProductVersion: 8.99.5763
FileDescription: Of The Software
OriginalFilename: Of The.exe
Translation: 0x0407 0x04b0

Trojan.Win32.Alien.vho also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.29339
MicroWorld-eScanTrojan.GenericKD.43383649
CAT-QuickHealTrojan.Alien
McAfeeRDN/Generic.grp
CylanceUnsafe
AegisLabTrojan.Win32.Vobfus.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderTrojan.GenericKD.43383649
K7GWTrojan ( 005697cd1 )
K7AntiVirusTrojan ( 005697cd1 )
TrendMicroTrojanSpy.Win32.ALIEN.USMANJR20
CyrenW32/Trojan.KMTA-5378
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Injector.Autoit.FBU
TrendMicro-HouseCallTrojanSpy.Win32.ALIEN.USMANJR20
AvastWin32:Trojan-gen
ClamAVWin.Dropper.NetWire-9200863-0
KasperskyHEUR:Trojan.Win32.Alien.vho
AlibabaTrojan:Win32/Vobfus.7489df77
NANO-AntivirusTrojan.Win32.Vobfus.hntchq
ViRobotTrojan.Win32.S.Agent.882192
TencentWin32.Trojan.Vobfus.Sudq
Ad-AwareTrojan.GenericKD.43383649
EmsisoftTrojan.Autoit (A)
F-SecureTrojan.TR/Agent.aps
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/Generic.grp
FireEyeTrojan.GenericKD.43383649
SophosMal/Generic-S
IkarusTrojan.Barys
MaxSecureTrojan.Malware.74662763.susgen
AviraTR/Agent.aps
MicrosoftTrojan:Win32/Ymacco.AA80
ArcabitTrojan.Generic.D295FB61
ZoneAlarmHEUR:Trojan.Win32.Alien.vho
GDataTrojan.GenericKD.43383649
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.43383649
MAXmalware (ai score=100)
MalwarebytesSpyware.Oski
PandaTrj/Genetic.gen
APEXMalicious
SentinelOneDFI – Suspicious PE
eGambitPE.Heur.InvalidSig
FortinetAutoIt/Injector.FBK!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.b8f

How to remove Trojan.Win32.Alien.vho?

Trojan.Win32.Alien.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment