Trojan

About “Trojan.Win32.Staser.vho” infection

Malware Removal

The Trojan.Win32.Staser.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Staser.vho virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Staser.vho?


File Info:

crc32: 277C60DF
md5: 38f4964893a281f0278e787cc491351b
name: hpii0wycj9bjl.exe
sha1: bd6f08b49168fde2f0ba66a9e93c13f22bca7fb9
sha256: ed5137c0f9798d552c71d2dcc0887e494f47fd022dbd4b0c1a0d8838f167a736
sha512: 7178cdc508ed3a525cdc4e6d9e02af857cfc7a3200e37d8d8c06c5b54447910b6d829fc2221089108e6f14135e1b3bf552df80b3717bafb9ea4ef1d416e12658
ssdeep: 12288:nUILKCNARjwrJ8//CIrqs8hXbfytwX2ZN:fS5qJ8/JrqsiutwX2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2002
InternalName: Visual Editor
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Visual Editor x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: Visual Editor x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: Visual Editor.EXE
Translation: 0x0804 0x04b0

Trojan.Win32.Staser.vho also known as:

MicroWorld-eScanTrojan.GenericKD.42075100
FireEyeGeneric.mg.38f4964893a281f0
McAfeeRDN/Emotet
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42075100
K7GWRiskware ( 0040eff71 )
SymantecTrojan Horse
APEXMalicious
ClamAVWin.Trojan.Generic-7419910-0
GDataTrojan.GenericKD.42075100
KasperskyHEUR:Trojan.Win32.Staser.vho
ViRobotTrojan.Win32.Z.Emotet.688623
RisingTrojan.Kryptik!1.BFB8 (CLASSIC)
Endgamemalicious (high confidence)
ComodoMalware@#1zif7xbyqkz2d
F-SecureTrojan.TR/AD.Emotet.dzoj
DrWebTrojan.DownLoader30.46648
SophosMal/Encpk-AOZ
IkarusTrojan-Banker.Emotet
CyrenW32/Trojan.DZFP-9360
JiangminTrojan.Banker.Emotet.mpz
AviraTR/AD.Emotet.dzoj
MAXmalware (ai score=83)
Antiy-AVLTrojan[Banker]/Win32.Emotet
ArcabitTrojan.Generic.D28203DC
ZoneAlarmHEUR:Trojan.Win32.Staser.vho
MicrosoftTrojan:Win32/Emotet!MTB
AhnLab-V3Trojan/Win32.Trickbot.R301638
VBA32Trojan.Emotet
ALYacTrojan.Agent.Emotet
Ad-AwareTrojan.GenericKD.42075100
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32Win32/Emotet.BN
TrendMicro-HouseCallTROJ_GEN.R03BC0DL219
TencentMalware.Win32.Gencirc.101c3e54
FortinetW32/TrickBot.CJ!tr
BitDefenderThetaGen:NN.ZexaE.32519.Qq1@ay7RJAgj
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.e1f

How to remove Trojan.Win32.Staser.vho?

Trojan.Win32.Staser.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment