Trojan

Trojan.Win32.Witch.ivx (file analysis)

Malware Removal

The Trojan.Win32.Witch.ivx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Witch.ivx virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Witch.ivx?


File Info:

name: 5277F3273D31C2E31F39.mlw
path: /opt/CAPEv2/storage/binaries/b82932a76167c8edc70b23c9a1e78cf85aec2673bea84651de956c6dd79d3cf8
crc32: 8B13D073
md5: 5277f3273d31c2e31f3907749a762416
sha1: e555a104e8f49efaef5dd16c62f57fcffaf80a3a
sha256: b82932a76167c8edc70b23c9a1e78cf85aec2673bea84651de956c6dd79d3cf8
sha512: 87a041d443390be8437a80e7d0ef8a468184d66d8bb058e4858112029b99d032dc22563f166bbbf46e90fe39ab94be490be4748e784f65498d1ef25c7488c08e
ssdeep: 768:7sRE9MtttttttttttttttHtttGH2GY6U1zlvU9xHup0iPQTKHd0CdmnbeGz4/Kit:7s2paFutiPYKHubeoMzxBUNYr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D743BF2BBBA0C4E4EC7BDDF60095EBB5E74ED81030685512BF0DA3AD1889D5F03E6166
sha3_384: 54019803906b6cbe6f177e15649d549dd073450b8bc5aacecdce9a6389ab6e9653eae20c88fcf90d882d09e5de5fbeb9
ep_bytes: 64a1300000008d2424908d2424fc83c0
timestamp: 2011-01-29 20:49:26

Version Info:

0: [No Data]

Trojan.Win32.Witch.ivx also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.47122
FireEyeGeneric.mg.5277f3273d31c2e3
CAT-QuickHealTrojan.IgenericRI.S26222255
McAfeeGenericRXAA-AA!5277F3273D31
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058dc961 )
BitDefenderGen:Variant.Midie.47122
K7GWTrojan ( 0058dc961 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Cosmu.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.OKR
APEXMalicious
ClamAVWin.Malware.Midie-9936226-0
KasperskyTrojan.Win32.Witch.ivx
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingMalware.Heuristic!ET#88% (RDMK:cmRtazoNFurETL3I9v6nSylDvFVy)
SophosMal/Generic-R + Mal/Inject-CG
DrWebTrojan.MulDrop19.27452
TrendMicroTROJ_KRYPTK.SM10
McAfee-GW-EditionBehavesLike.Win32.Downloader.qh
EmsisoftGen:Variant.Midie.47122 (B)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.ZPACK.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Midie.47122
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Gampass.R467614
BitDefenderThetaAI:Packer.42DDA7C71E
ALYacGen:Variant.Midie.47122
VBA32Malware-Cryptor.Win32.General.4
MalwarebytesMalware.AI.3766743511
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SM10
YandexTrojan.GenAsa!g4uRYh33TJE
MAXmalware (ai score=89)
FortinetW32/Cosmu.AO!tr
AVGWin32:Agent-AMRX [Trj]
Cybereasonmalicious.73d31c
AvastWin32:Agent-AMRX [Trj]

How to remove Trojan.Win32.Witch.ivx?

Trojan.Win32.Witch.ivx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment