Trojan

Trojan.Win32.Witch.gyl removal instruction

Malware Removal

The Trojan.Win32.Witch.gyl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Witch.gyl virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects VirtualBox using WNetGetProviderName trick
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Appears to use command line obfuscation
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to disable Windows Defender
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Witch.gyl?


File Info:

name: AB175117B5379F7579D5.mlw
path: /opt/CAPEv2/storage/binaries/dc4606affdce76777761d01ee85478775a0f2730f729e2be5552370d0be26ec5
crc32: 5BD71D1A
md5: ab175117b5379f7579d5d4a148b400a4
sha1: f972c9472e24cd83e0611ff4398ed6fd91a94b86
sha256: dc4606affdce76777761d01ee85478775a0f2730f729e2be5552370d0be26ec5
sha512: b2f998d137093061acfc8f79c723184f73022b964d750496778d6efcfba20b25e1ccd037be345e34c2d40e48b4fb272868eca2e6879a0a93603c4dca5eae7b6a
ssdeep: 196608:91O0RTXME2k5G1TVKsUkmeDqslK9xRqPd1:3OEMdk5G1xl3mmHlkxR41
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C5633657CF18CFBE9915270DAAA7F8EB9FDE60069212C6337DE625E043C28440FA553
sha3_384: 690e0a55b8b4b278b4565db9e98b82efa42345aa4046b29158c5f812694526859346e55c3613d39cdf179a04778fcbd8
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

Trojan.Win32.Witch.gyl also known as:

LionicTrojan.Win32.Witch.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.48175
FireEyeGen:Variant.Jaik.48175
McAfeeArtemis!AB175117B537
CylanceUnsafe
K7AntiVirusAdware ( 00581e241 )
AlibabaTrojan:Win32/Witch.b63cbb36
K7GWAdware ( 00581e241 )
BitDefenderThetaGen:NN.ZexaF.34084.@JW@a4r7g1f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.LI
TrendMicro-HouseCallTROJ_GEN.R002C0PL221
Paloaltogeneric.ml
KasperskyTrojan.Win32.Witch.gyl
BitDefenderGen:Variant.Jaik.48175
NANO-AntivirusRiskware.Win32.Neoreklami.jiqhkv
AvastWin32:MiscX-gen [PUP]
TencentWin32.Trojan.Witch.Lmap
Ad-AwareGen:Variant.Jaik.48175
EmsisoftGen:Variant.Jaik.48175 (B)
DrWebTrojan.MulDrop19.10015
TrendMicroTROJ_GEN.R002C0PL221
McAfee-GW-EditionPUP-XQN-DN
SophosGeneric PUA HG (PUA)
IkarusPUA.Neoreklami
GDataGen:Variant.Jaik.48175
AviraHEUR/AGEN.1106374
MAXmalware (ai score=85)
Antiy-AVLGrayWare[AdWare]/Win32.Neoreklami
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Jaik.DBC2F
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32Trojan.Sdum
ALYacGen:Variant.Jaik.48175
MalwarebytesAdware.Neoreklami
RisingTrojan.Generic@ML.87 (RDMK:Lhoe5pDPj1JP/4eLP0VM1g)
YandexTrojan.Witch!4g9IXk+kTyI
SentinelOneStatic AI – Malicious SFX
FortinetAdware/Neoreklami
AVGWin32:MiscX-gen [PUP]

How to remove Trojan.Win32.Witch.gyl?

Trojan.Win32.Witch.gyl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment