Trojan

VHO:Trojan-PSW.Win32.Taurus removal instruction

Malware Removal

The VHO:Trojan-PSW.Win32.Taurus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-PSW.Win32.Taurus virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

villiambutcher.com
ip-api.com

How to determine VHO:Trojan-PSW.Win32.Taurus?


File Info:

crc32: BEF7D6D4
md5: e3fdfa735b5e38aeb879fbc60956fc4c
name: E3FDFA735B5E38AEB879FBC60956FC4C.mlw
sha1: 02bbf275d999afe8c7e1dd8c76261e76acb2cc22
sha256: 5f876793ede5e8f39e1e06ff2f5bdc88d08b69d739fb67f20e4feded2486a7b2
sha512: 38dae1d8fbe6ab4bd5c0efdb5ce35e56d4b33de249526c9963fc78f3b4c9cb2995249ac182cde54ed46660b51e69a7e09b72cbbd082602912f1ba0c96d7e6e68
ssdeep: 6144:KRkvhZCOQv1Pb2j/IqgCyM4h5WeSeSRZeWdBNx3Qpht8QJSl5WoJWGC+okv:KRkwv1PUgM4hACS3DdBAWQEr8GC+J
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

VHO:Trojan-PSW.Win32.Taurus also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056f9be1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S18039805
ALYacGen:Heur.Mint.Titirez.Bv0@ZyCapapG
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0056f9be1 )
Cybereasonmalicious.35b5e3
CyrenW32/Kryptik.CXK.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HIMZ
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Packed.Bulz-9819346-0
KasperskyVHO:Trojan-PSW.Win32.Taurus.gen
BitDefenderGen:Heur.Mint.Titirez.Bv0@ZyCapapG
MicroWorld-eScanGen:Heur.Mint.Titirez.Bv0@ZyCapapG
Ad-AwareGen:Heur.Mint.Titirez.Bv0@ZyCapapG
SophosML/PE-A
BitDefenderThetaAI:Packer.975A182621
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
FireEyeGeneric.mg.e3fdfa735b5e38ae
EmsisoftGen:Heur.Mint.Titirez.Bv0@ZyCapapG (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Stealer.dno
AviraTR/Crypt.XPACK.Gen5
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASCommon.1E7
MicrosoftRansom:Win32/StopCrypt.MK!MTB
ArcabitTrojan.Mint.Titirez.E5F408
GDataGen:Heur.Mint.Titirez.Bv0@ZyCapapG
AhnLab-V3Malware/Win32.RL_Generic.R361972
Acronissuspicious
McAfeeLockbit-FSWW!E3FDFA735B5E
MAXmalware (ai score=89)
VBA32BScope.Exploit.Shellcode
MalwarebytesTrojan.MalPack.GS
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazroF4z8Z1Ue0Zz/Eoz32d9R)
IkarusTrojan.Win32.Azorult
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]

How to remove VHO:Trojan-PSW.Win32.Taurus?

VHO:Trojan-PSW.Win32.Taurus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment