Trojan

Should I remove “VHO:Trojan-PSW.Win32.Stealer.kag”?

Malware Removal

The VHO:Trojan-PSW.Win32.Stealer.kag is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-PSW.Win32.Stealer.kag virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Icelandic
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VHO:Trojan-PSW.Win32.Stealer.kag?


File Info:

crc32: 836A73E0
md5: 42d8a218327e333e82ea989abfaa6538
name: 42D8A218327E333E82EA989ABFAA6538.mlw
sha1: a6bc11e574bf1194b57d40c7201cb96abb6b234a
sha256: f49f39d84bcc83faeefa0d0606c886c4a06cac3c2cd6c5b3b938a2f1b76a8d1f
sha512: d7b9b2ee1f239d2a007f20d6c7d8846ffa4c1f2c419b657944754b84e4044563b841340fcba87a9bfdaf2a662cb54dc94b94c27200c2f245c51045f327ab4b3e
ssdeep: 6144:OS8uLU5bDm3LpD/aGwPvSytLxGXKqH4pdv/a5VLcQKUfIanX59EPCmK:p8u452JS1PvS68XIiKUwaX59Y
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmiiloku.apa
ProductVersion: 7.12.29.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0181 0x009f

VHO:Trojan-PSW.Win32.Stealer.kag also known as:

Elasticmalicious (high confidence)
ClamAVWin.Malware.Razy-9889631-0
ALYacGen:Variant.Razy.914220
MalwarebytesSpyware.PasswordStealer
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderGen:Variant.Razy.914220
Cybereasonmalicious.7e22a8
ESET-NOD32a variant of Win32/Packed.Enigma.FH
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-PSW.Win32.Stealer.kag
MicroWorld-eScanGen:Variant.Razy.914220
Ad-AwareGen:Variant.Razy.914220
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZemsilF.34110.Gy2@aaYLiy
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.c4942ae23f119444
EmsisoftTrojan-Spy.Agent (A)
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
MicrosoftTrojan:Script/Phonzy.C!ml
GridinsoftTrojan.Heur!.01012031
GDataWin32.Trojan.PSE.1MFCAJH
AhnLab-V3Trojan/Win.Generic.C4611711
Acronissuspicious
McAfeeGenericRXPV-KU!C4942AE23F11
MAXmalware (ai score=86)
PandaTrj/Genetic.gen
FortinetW32/Agent.EF41!tr

How to remove VHO:Trojan-PSW.Win32.Stealer.kag?

VHO:Trojan-PSW.Win32.Stealer.kag removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment