Trojan

Should I remove “Trojan.Win32.Tremp.vho”?

Malware Removal

The Trojan.Win32.Tremp.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Tremp.vho virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Tremp.vho?


File Info:

name: 4A06FE85D5FBE851B43B.mlw
path: /opt/CAPEv2/storage/binaries/9f7d96294bb61c5853f96b8d292c4e3b5c00dbe45b4a129ab85d12358e2bf731
crc32: E0BDAC53
md5: 4a06fe85d5fbe851b43b11e7fe6d254f
sha1: 8cc99c90c6d0b4a09e08d87c07d894a1b587a818
sha256: 9f7d96294bb61c5853f96b8d292c4e3b5c00dbe45b4a129ab85d12358e2bf731
sha512: 748c7174028098a850d3de5ff866e91496ae33c09456199c1313dd3cc48095244e44e9aa47ed0147806abfe077b5df702446936bf6ad44a759604a8e8e3e5ac7
ssdeep: 98304:+BzVpxa2K6HeHLU3RcMaG+bT9s9NCYXYYhhizQ2giGaTbDvUCoXyjrjQnECNuI:8hpw6HeIRcJ9bT+9hXlhizQravDvksQ5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0462212B6C2C0F2C03202B4153EB73616BFB971447595BBABE5CE9A1D70181FB67A63
sha3_384: 4ba31e3c0638c20bdbedeff22fe206ab218377a6eeaf93fa7eeee614d966d66752e9656ef754f9d5def3caf8b55ae4d1
ep_bytes: e89b480000e8f347000033c0c3909090
timestamp: 2018-04-26 18:02:16

Version Info:

0: [No Data]

Trojan.Win32.Tremp.vho also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Dinwod.mgDt
tehtrisGeneric.Malware
FireEyeGeneric.mg.4a06fe85d5fbe851
CAT-QuickHealRansom.Genasom.16527
McAfeeArtemis!4A06FE85D5FB
CylanceUnsafe
SangforTrojan.Win32.Save.BlackMoon
AlibabaTrojan:Win32/Miners.30b0626d
Cybereasonmalicious.5d5fbe
BitDefenderThetaGen:NN.ZexaF.34726.@pW@auLOo!i
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyHEUR:Trojan.Win32.Tremp.vho
NANO-AntivirusTrojan.Win32.Hijacker.faueff
AvastWin32:Malware-gen
ComodoMalware@#3vxlr7gndp9wc
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.high.ml.score
SophosGeneric PUA IM (PUA)
GDataWin32.Trojan.Agent.WP
JiangminTrojan.Generic.acn
GoogleDetected
AviraTR/Hijacker.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3C54
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
MAXmalware (ai score=99)
VBA32BScope.Trojan.MulDrop
RisingTrojan.Injector!1.A1C3 (CLOUD)
YandexTrojan.GenAsa!8I2QBm96rm8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.BBYK!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Tremp.vho?

Trojan.Win32.Tremp.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment