Trojan

What is “VHO:Trojan-PSW.Win32.RisePro”?

Malware Removal

The VHO:Trojan-PSW.Win32.RisePro is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-PSW.Win32.RisePro virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine VHO:Trojan-PSW.Win32.RisePro?


File Info:

name: C1176D9D169FF8A48EA3.mlw
path: /opt/CAPEv2/storage/binaries/7fd6daf44e77314416c2ae842ef3b1b6e3c909c5ed721b6e31c3f110cc8a679e
crc32: ABF0AF36
md5: c1176d9d169ff8a48ea378bfa296e6df
sha1: a33be117c2bea5128dedbd42c31afac4b6c47cf8
sha256: 7fd6daf44e77314416c2ae842ef3b1b6e3c909c5ed721b6e31c3f110cc8a679e
sha512: b71f081ca441a42d08cb4d83f7e2753026118c96dd56b95c1842f9d52ecfaa39f543c5c7e3aa66d0e9ff89dc2c6fae9fbd8e453dcfe614ae455de4397d8f175c
ssdeep: 49152:o2dueVHtvOgquseDukEiMWqDy7poCUEV1wPe2hyiPnI:LdHMopEiB33ee0/PI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B29523F133F8859DD6C84BF54BB0951242E06DC9CF211EEAC9EB28177B1B2C1162A74B
sha3_384: dac6b92771e3ca38129e15d46fc0c74cbdbd1a38ecc8f8740e22a836f8b72aaa9a52ae6026bed22feb2d9bfd312f5b85
ep_bytes: eb0800260d000000000060e800000000
timestamp: 2024-01-06 14:44:07

Version Info:

CompanyName: The Enigma Protector Developers Team
FileDescription: Software Protection Tool
FileVersion: 1.0.0.0
InternalName: ENIGMA.EXE
LegalCopyright: Copyrights (C) 2002-2009 Vladimir Sukhov
LegalTrademarks: Trademarks (R) 2002-2009 Vladimir Sukhov
OriginalFilename: enigma.exe
ProductName: The Enigma Protector
ProductVersion: 1.0.0.0
Comments: http://enigmaprotector.com/
Translation: 0x0409 0x04b0

VHO:Trojan-PSW.Win32.RisePro also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MalwarebytesTrojan.MalPack
SangforSuspicious.Win32.Save.ins
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-PSW.Win32.RisePro.gen
AvastWin32:TrojanX-gen [Trj]
SophosGeneric ML PUA (PUA)
IkarusTrojan.Dropper.Agent
WebrootW32.Malware.Gen
GoogleDetected
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmVHO:Trojan-PSW.Win32.RisePro.gen
AhnLab-V3Trojan/Win.Generic.R630828
BitDefenderThetaGen:NN.ZexaF.36680.YH0@a0SAZNfk
VBA32Trojan.Wacatac
Cylanceunsafe
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove VHO:Trojan-PSW.Win32.RisePro?

VHO:Trojan-PSW.Win32.RisePro removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment