Trojan

What is “Trojan.Win32.Witch.ub”?

Malware Removal

The Trojan.Win32.Witch.ub is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Witch.ub virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Trojan.Win32.Witch.ub?


File Info:

crc32: EC56D976
md5: 234fc480aa05036e95e5f475375f9802
name: 234FC480AA05036E95E5F475375F9802.mlw
sha1: d13d59195292f37591eaefc9c0394e483311127c
sha256: cc12d607d3fcc1577e50d5793ac7de691e4683ed9843676ec11863d3e2727e04
sha512: 69af3cba74b9f98ca5b52db31cddb645e22b3ba9e6094536880d75c41c297a5ff759075eb43c746a31f61cc72a3711540f1a1149b5d173c4908d337d68840503
ssdeep: 1536:0GDD7YHr54omvdQvMtXoxOphvdvYNqwKTqSp4aTlrdDLXnRp:0MYHr5HmogXooNeKuSOaTlpLXnRp
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Trojan.Win32.Witch.ub also known as:

K7AntiVirusTrojan ( 004f8bc31 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
ZillyaTrojan.Generic.Win32.86826
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Kryptik.c01655c8
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.0aa050
CyrenW32/S-b308e227!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Witch.ub
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentMalware.Win32.Gencirc.114d3e9f
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S + Mal/EncPk-AOI
ComodoMalware@#2066rjy8ifeu4
BitDefenderThetaGen:NN.ZexaF.34110.fy1@ae5bJKpU
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.234fc480aa05036e
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2823D89
MicrosoftRansom:Win32/Tovicrypt!rfn
ZoneAlarmTrojan.Win32.Witch.ub
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188042
Acronissuspicious
VBA32BScope.Trojan.Bagsu
MAXmalware (ai score=100)
MalwarebytesRansom.CryptXXX
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.100 (RDML:YFPnoHxFprazImfUBVhpTQ)
YandexTrojan.GenAsa!NrwxPak0V3U
IkarusTrojan-Ransom.Tovicrypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Witch.ub?

Trojan.Win32.Witch.ub removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment