Trojan

What is “Trojan.Win32.Witch.gfi”?

Malware Removal

The Trojan.Win32.Witch.gfi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Witch.gfi virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Attempts to disable Windows Defender

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Witch.gfi?


File Info:

crc32: 9A5B8A9B
md5: 65b7cdd9dfcb6feaf38dd0c22e2458a7
name: 65B7CDD9DFCB6FEAF38DD0C22E2458A7.mlw
sha1: e608336716812edbbf027a17189b25ce72c38c0f
sha256: 03e1cc7410e0295bd5ccf15aa7edee36d87475368877a43495e2ce530b0be659
sha512: decd3cb0f5d23556c01e109377d8fb5df886cde6e6d80974e59053f7305c7cbf88e503efe31ce336c47bb9adb766351e62fe976b91abea67941e45bd3ef61336
ssdeep: 196608:91OGQsqUTZWrXOhnU7PnyL+WYmELXiBlCKXCp:3OECXr76LlYmELyBgKyp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7z Setup SFX
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

Trojan.Win32.Witch.gfi also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Neoreklami
ALYacGen:Variant.Jaik.48175
CylanceUnsafe
SangforTrojan.Win32.Witch.gfi
AlibabaTrojan:Win32/Witch.b83e1420
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.LI
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyTrojan.Win32.Witch.gfi
BitDefenderGen:Variant.Jaik.48175
ViRobotAdware.Neoreklami.6545833
MicroWorld-eScanGen:Variant.Jaik.48175
Ad-AwareGen:Variant.Jaik.48175
SophosGeneric PUA OG (PUA)
BitDefenderThetaGen:NN.ZexaF.34266.@JW@a8kWuh
TrendMicroTROJ_GEN.R002C0PJS21
McAfee-GW-EditionGenericRXQG-KA!B1172FC4B1F6
FireEyeGen:Variant.Jaik.48175
EmsisoftGen:Variant.Jaik.48175 (B)
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.Multi.equ
AviraADWARE/Neoreklami.nqwka
Antiy-AVLTrojan/Generic.ASMalwS.34C5C91
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmTrojan.Win32.Witch.gfi
GDataGen:Variant.Jaik.48175
McAfeeArtemis!65B7CDD9DFCB
MAXmalware (ai score=84)
VBA32Trojan.Wacatac
MalwarebytesAdware.Neoreklami
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H07JS21
RisingTrojan.Generic@ML.88 (RDMK:Tpw/GvSfvteRFFwa0WrjuA)
YandexTrojan.Witch!ehUX0ccCLyk
IkarusPUA.Neoreklami
FortinetAdware/Neoreklami
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Trojan.Win32.Witch.gfi?

Trojan.Win32.Witch.gfi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment