Trojan

How to remove “Trojan.Win32.Witch.bpl”?

Malware Removal

The Trojan.Win32.Witch.bpl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Witch.bpl virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Trojan.Win32.Witch.bpl?


File Info:

crc32: 6B6B4F93
md5: af4deab899925d143556569811862d4d
name: AF4DEAB899925D143556569811862D4D.mlw
sha1: 6ccbdb8303541ba202f25a42f36a6994e169dd8b
sha256: c76dee48164e3e1484eaa729cefd5d2a27e079349c548ffb27ad28fb0e7e534e
sha512: fd2dce2f53ba01bd75e7b8738ff377d169319e7c940ab479d3d642a28b925b5a28e36e125a1610f26367c9f0646b9e25f0b8a0105f255d84d481266d71cc8236
ssdeep: 3072:Nm8zvs5maI9q/vJaz8taj4dYg0nhE3lzLXn6vH:cSvvaIHz8ddYxhEJLX6
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: NirCmd
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Trojan.Win32.Witch.bpl also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f8bc31 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.4865
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.MUE.A6
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.899925
CyrenW32/S-ef537a26!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Goblinek [Inf]
KasperskyTrojan.Win32.Witch.bpl
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Kryptik.evmidl
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentWin32.Trojan.Generic.Lort
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.gy0@aOJMAcfU
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.af4deab899925d14
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128192
Antiy-AVLTrojan/Generic.ASMalwS.22DAE7D
MicrosoftRansom:Win32/Tovicrypt!rfn
ArcabitTrojan.Ransom.CryptXXX.1
ZoneAlarmTrojan.Win32.Witch.bpl
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.C1567206
Acronissuspicious
McAfeeRansomware-FTK!AF4DEAB89992
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.2028257381
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.100 (RDML:3KFGxnVNIBmF4hqAWDf9jw)
YandexTrojan.GenAsa!rPlCHhCY5Gw
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Goblinek [Inf]
Paloaltogeneric.ml

How to remove Trojan.Win32.Witch.bpl?

Trojan.Win32.Witch.bpl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment