Trojan

About “Trojan.Win32.Mucc.vho” infection

Malware Removal

The Trojan.Win32.Mucc.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Mucc.vho virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Mucc.vho?


File Info:

name: 3945B9A6746BC0BC1F9A.mlw
path: /opt/CAPEv2/storage/binaries/2997d169c77dffeb7aa183a5740063e32ca19410b6b28bb5a44a8b8e751ddff3
crc32: AF9435AE
md5: 3945b9a6746bc0bc1f9a092575847073
sha1: c4bc12142848c168f6aaf2999a95f276a27488ad
sha256: 2997d169c77dffeb7aa183a5740063e32ca19410b6b28bb5a44a8b8e751ddff3
sha512: b5e9f9a58b2ea4447a6110c424f459c7fc058f1af4255f4367c853e3111425c3e4b2d0a963be9c72899b1e6f8ca55ad417c51d73f7c4f1630cc113078a523a37
ssdeep: 24576:qztqFZKfRPQzFyCPjQg8fBEDTgIkk8DRlvi2wdL+rkEHk9+:q4X1PQk9+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185354A65F8AB54B9F60E52B24CE346AF333676055B33DAC3C6409AA5FD47BE02C32125
sha3_384: 180c32f95301fcbd5a428a3906be0a8512f301d8c5620214c9857260692a9c45ed041195c916b6f0bc655db1141d0339
ep_bytes: e9dbd8ffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Mucc.vho also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mucc.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.3945b9a6746bc0bc
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXLU-IZ!3945B9A6746B
MalwarebytesGeneric.Malware/Suspicious
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b1601 )
AlibabaTrojan:Win32/Generic.4f3669e7
K7GWTrojan ( 0001b1601 )
BitDefenderThetaGen:NN.ZexaF.36802.fvW@aODiZUe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.TSI
APEXMalicious
KasperskyHEUR:Trojan.Win32.Mucc.vho
NANO-AntivirusTrojan.Win32.Ursu.hmfhws
AvastWin32:Trojan-gen
TencentWin32.Trojan.Mucc.Ltgl
F-SecureTrojan.TR/Crypt.XPACK.Gen
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Mucc.ayy
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Kingsoftmalware.kb.a.771
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumMalware@#142wv30e3k0jg
ZoneAlarmHEUR:Trojan.Win32.Mucc.vho
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.R351743
VBA32BScope.Trojan.Tiggre
RisingTrojan.Generic@AI.100 (RDMK:NaxRzLXyoxKbevtCPy/H0Q)
YandexTrojan.Agent!iRa4nLLQ9LE
IkarusTrojan.Win32.Agent
FortinetW32/Agent.TSI!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Mucc.vho?

Trojan.Win32.Mucc.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment