Trojan

Trojan.Win32.Witch.ivu malicious file

Malware Removal

The Trojan.Win32.Witch.ivu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Witch.ivu virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Witch.ivu?


File Info:

name: 1C9A7FE5F531E2ABADF8.mlw
path: /opt/CAPEv2/storage/binaries/cfceeb20ccbf5b190d081b2a89c505ef44328cb97760d42a8ce8a5ff1d9e0ea0
crc32: 7D3875C1
md5: 1c9a7fe5f531e2abadf8c33bdca35155
sha1: 0a89e3c9656a79480f48ed3e19f2e91ec609e222
sha256: cfceeb20ccbf5b190d081b2a89c505ef44328cb97760d42a8ce8a5ff1d9e0ea0
sha512: 3d4e4ef174c67ce5f83d5c76ad9740f244ce067d0f9e96a77486f66f40fdf4d4a24770ab10ce6a1a2ca326b9f032fe2f743912a2b39defc0e319b5e2582eac0c
ssdeep: 768:ddm5jE/3ODc4C6Dzh50jAyXsLcCV/bE/D0EHAbL9qokf6AyM3givf:dgFc6xyXsAC5yD0E8LUj6M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE43F21FA63954D1C929EE7DFAFB1F6A08EC20353243AD326A4E08F622A5D445CC54CB
sha3_384: feee87c9a500cd581bfa222bdaef965b95cc12bbd6ead4b8402eeccdfa8a1ceafb1d56030d7d932736af83a58fb5f426
ep_bytes: 64a13000000004042c0424ff33c133c1
timestamp: 2011-01-29 20:49:26

Version Info:

0: [No Data]

Trojan.Win32.Witch.ivu also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.47122
FireEyeGeneric.mg.1c9a7fe5f531e2ab
CAT-QuickHealTrojan.IgenericRI.S26222255
McAfeeGenericRXAA-AA!1C9A7FE5F531
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058dc961 )
K7GWTrojan ( 0058dc961 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.D7CF72C01E
CyrenW32/Cosmu.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.OKR
TrendMicro-HouseCallTROJ_KRYPTK.SM10
Paloaltogeneric.ml
ClamAVWin.Malware.Midie-9936226-0
KasperskyTrojan.Win32.Witch.ivu
BitDefenderGen:Variant.Midie.47122
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Agent-AMRX [Trj]
EmsisoftGen:Variant.Midie.47122 (B)
TrendMicroTROJ_KRYPTK.SM10
McAfee-GW-EditionBehavesLike.Win32.RAHack.qc
SophosML/PE-A + Mal/Inject-CG
IkarusTrojan.Win32.Cosmu
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan.Win32.Witch.ivu
GDataGen:Variant.Midie.47122
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Gampass.R467614
VBA32Malware-Cryptor.Win32.General.4
ALYacGen:Variant.Midie.47122
MalwarebytesMalware.AI.3766743511
APEXMalicious
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazqJPzAgdffm7jfZ9Tf1brlg)
YandexTrojan.GenAsa!g4uRYh33TJE
SentinelOneStatic AI – Malicious PE
FortinetW32/Cosmu.AO!tr
AVGWin32:Agent-AMRX [Trj]
Cybereasonmalicious.5f531e
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Witch.ivu?

Trojan.Win32.Witch.ivu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment