Spy Trojan

What is “VHO:Trojan-Spy.Win32.Windigo”?

Malware Removal

The VHO:Trojan-Spy.Win32.Windigo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Spy.Win32.Windigo virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:14656
  • A process created a hidden window
  • Unconventionial language used in binary resources: Sanskrit
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Attempts to execute a powershell command with suspicious parameter/s
  • Collects information about installed applications
  • Likely virus infection of existing system binary
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VHO:Trojan-Spy.Win32.Windigo?


File Info:

crc32: 7478EECA
md5: 91a0997b88bc9bfef63bb6927970a34c
name: 91A0997B88BC9BFEF63BB6927970A34C.mlw
sha1: 0a19e7200f63428bb0d19c7dc55e3aa3813ea4fa
sha256: 906efd7add6d31aa8e871c5b63aa56a3987a0d5fd38267998c2dc1f6c2ad2e44
sha512: 8a73640573bef2648e0f608be7c95aff50925a9615fc5cd0f0e071deba976f7e9490c3f5d3e5fa2827c5ea1a3d715cd0c85ec9151c050d3f4817b7e4294f36d4
ssdeep: 98304:1WKa5/kkitY6T3Qt29Uqdi3/y6IWAkxFznGd+CF1dtZmaGKvajAVo9I84img5qU:1WKa5/BiGLok3qtWA+FzGdl9Rajqwhd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVers: 7.0.21.21
LegalCopyrighd: Jdfgl sfd
InternalNames: galimatimot
Translations: 0x0148 0x1823

VHO:Trojan-Spy.Win32.Windigo also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.00f634
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyVHO:Trojan-Spy.Win32.Windigo.gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34686.@BW@a8C4kViO
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.91a0997b88bc9bfe
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1107247
eGambitUnsafe.AI_Score_60%
MicrosoftTrojan:Win32/Predator!ml
Acronissuspicious
McAfeePacked-GBF!91A0997B88BC
MalwarebytesTrojan.MalPack.GS

How to remove VHO:Trojan-Spy.Win32.Windigo?

VHO:Trojan-Spy.Win32.Windigo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment