Trojan

Trojan.Win32.Witch.gkf removal tips

Malware Removal

The Trojan.Win32.Witch.gkf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Witch.gkf virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Trojan.Win32.Witch.gkf?


File Info:

crc32: 11E12C6C
md5: 566861220a8d7c1091292fa79ee71174
name: 566861220A8D7C1091292FA79EE71174.mlw
sha1: 4b490bdebeec003a9c632c8df861dd4c7b2598aa
sha256: f3fdf882491dce488f858943724cb973bdf0696b01eb7df1830380beae47f27f
sha512: f1a1e7c617c629d71261f4ef58806bb759b5225963d309ce776a9dd561600074604e117eac3dc7133310ce42f41d93e0f0a9130f6b0ea79f1e27e2057c8f8277
ssdeep: 196608:91Oka76hTpWYazQvFLxD2ZEOnU3kdidWD/ykUYcTulpL3g+C:3OkY6tUYoUVqdSWDyk5cEpL3tC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7z Setup SFX
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

Trojan.Win32.Witch.gkf also known as:

K7AntiVirusAdware ( 00581def1 )
LionicTrojan.Win32.Witch.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Jaik.48175
CylanceUnsafe
SangforTrojan.Win32.Witch.gkf
AlibabaAdWare:Win32/Neoreklami.e26ccdcd
K7GWAdware ( 00581def1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.LI
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyTrojan.Win32.Witch.gkf
BitDefenderGen:Variant.Jaik.48175
MicroWorld-eScanGen:Variant.Jaik.48175
Ad-AwareGen:Variant.Jaik.48175
SophosGeneric PUA EL (PUA)
BitDefenderThetaGen:NN.ZexaF.34266.@JW@a0D3kxb
TrendMicroTROJ_GEN.R002C0WK421
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
FireEyeGen:Variant.Jaik.48175
EmsisoftGen:Variant.Jaik.48175 (B)
SentinelOneStatic AI – Malicious SFX
AviraTR/ATRAPS.Gen4
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.34C6C59
MicrosoftTrojan:Win32/Woreflint.A!cl
GDataGen:Variant.Jaik.48175
McAfeeArtemis!566861220A8D
MAXmalware (ai score=83)
VBA32Trojan.Sdum
MalwarebytesAdware.Neoreklami
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H07K421
RisingTrojan.Generic@ML.86 (RDMK:6P5XG+xcBL1O/bpXKdpbOA)
FortinetAdware/Neoreklami
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Trojan.Win32.Witch.gkf?

Trojan.Win32.Witch.gkf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment