Trojan

About “VHO:Trojan.Win32.Kolovorot” infection

Malware Removal

The VHO:Trojan.Win32.Kolovorot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan.Win32.Kolovorot virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.2345.com
ocsp.digicert.cn
crl.digicert.cn
h2.2345cdn.net

How to determine VHO:Trojan.Win32.Kolovorot?


File Info:

crc32: ADD4690C
md5: d98d1885ecc4b1397cc9425bf514a567
name: D98D1885ECC4B1397CC9425BF514A567.mlw
sha1: 89832ecc252610c636cfeac5987dd7e5fcc6e4ae
sha256: adb57666a8900752d34d0208e5ddd6fdc2508277faad4a509f9a2c1caeda06a9
sha512: d8c92054e5fb9efe504f35fa334de17e0e262961c7aa31de9617d599b4557cf03795f34ee62fb91500810a1386b3ee9399de77c6782d9fef8ddaad195eed29df
ssdeep: 12288:A4x5Fz5MNSiitDz4fu2AbL1OvTLjES3X/ykbIIBPMWQy3N/ykbIIBPA:AuFdkS7tDz4COzdXqbUlQONqbU4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5c0fx6656x6240x6709x6743
FileVersion: 1.0.0.0
CompanyName: x5c0fx6656
Comments: x77edx4fe1x8f70x70b8
ProductName: x5c0fx6656x77edx4fe1x8f70x70b8x673a
ProductVersion: 1.0.0.0
FileDescription: x77edx4fe1x8f70x70b8
Translation: 0x0804 0x04b0

VHO:Trojan.Win32.Kolovorot also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Win32.Generic.lpDo
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Kolovorot.gen
BitDefenderTrojan.GenericKD.47333395
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.c25261
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Kolovorot.gen
AlibabaTrojanDropper:Win32/BScope.c36a21b7
MicroWorld-eScanTrojan.GenericKD.47333395
Ad-AwareTrojan.GenericKD.47333395
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionGenericRXAK-KK!D98D1885ECC4
FireEyeGeneric.mg.d98d1885ecc4b139
EmsisoftTrojan.GenericKD.47333395 (B)
eGambitUnsafe.AI_Score_90%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.11B5R9D
Acronissuspicious
McAfeeGenericRXAK-KK!D98D1885ECC4
MAXmalware (ai score=84)
VBA32BScope.Adware.Agent
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H0CK521
RisingTrojan.Generic@ML.81 (RDML:PLLymU5O6EL4BHPpnHKlSA)
YandexTrojan.GenAsa!cKuRrlohVec
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
Paloaltogeneric.ml

How to remove VHO:Trojan.Win32.Kolovorot?

VHO:Trojan.Win32.Kolovorot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment