Trojan

About “VHO:Trojan.Win32.Selfmod” infection

Malware Removal

The VHO:Trojan.Win32.Selfmod is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan.Win32.Selfmod virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VHO:Trojan.Win32.Selfmod?


File Info:

name: 2D206750EC787D50B61E.mlw
path: /opt/CAPEv2/storage/binaries/60ff45185ace4ba17910895042524101fbad7377cceba54d866e8b054b668ca1
crc32: 0EE7A993
md5: 2d206750ec787d50b61ee23ae66bd4cb
sha1: cb3b2a8b5d3d18e72abdc11c9983fe571a2c2f4b
sha256: 60ff45185ace4ba17910895042524101fbad7377cceba54d866e8b054b668ca1
sha512: eaaad660f1e7856c6bf9417795034a061c1a310aa5cb591c911bf512ac40c5122f01b278e85ad804cb0f24d35ada982623a3fe12eee2e827a9aff4cd0766891c
ssdeep: 12288:Og7PbqN5S8iT2+6ntCmTjVDa/ZS4fD7HnhvMCtjW:OgDbqnVBa/ZS4fDDueC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11F35485D1EDD8173EC06523E69DEAF2260106F7D261BFEA137A0BE763EE17C19106620
sha3_384: 85333e4bd992b1ff8e8946a2fa06f6799b57555e780c624cda1ed9a2f84a02bd08ae122dca82a254468131a46f8dc758
ep_bytes: 035019a953399d2e56d894bfd492fc05
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

VHO:Trojan.Win32.Selfmod also known as:

tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.98348
ClamAVWin.Packed.Dridex-9860931-1
ALYacTrojan.GenericKDZ.98348
MalwarebytesCrypt.Trojan.MSIL.DDS
VIPRETrojan.GenericKDZ.98348
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.b5d3d1
BitDefenderThetaGen:NN.ZexaF.36196.e9Z@ai!cyWb
CyrenW32/Zusy.EM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Selfmod.gen
BitDefenderTrojan.GenericKDZ.98348
NANO-AntivirusTrojan.Win32.Packed2.gmlrvu
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftTrojan.GenericKDZ.98348 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
ZillyaTrojan.Generic.Win32.262308
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.th
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.2d206750ec787d50
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11YPVZ
JiangminTrojan.Copak.crjg
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Win32.Kryptik.GIFY
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D1802C
ZoneAlarmVHO:Trojan.Win32.Selfmod.gen
MicrosoftTrojan:Win32/Glupteba.MT!MTB
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5394145
McAfeePacked-FJB!2D206750EC78
MAXmalware (ai score=83)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove VHO:Trojan.Win32.Selfmod?

VHO:Trojan.Win32.Selfmod removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment