Trojan

Should I remove “VHO:Trojan.Win32.Tremp”?

Malware Removal

The VHO:Trojan.Win32.Tremp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan.Win32.Tremp virus can do?

  • Dynamic (imported) function loading detected
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine VHO:Trojan.Win32.Tremp?


File Info:

name: 2153AFAF9815C1AF275D.mlw
path: /opt/CAPEv2/storage/binaries/9438638a6962ac39926b3d5dbe88a59bd5cfccf4518d54371994fb92973f0cdb
crc32: D4686482
md5: 2153afaf9815c1af275dad0bdb53a9e4
sha1: 8513e0dba745126aa1f4c8a5236ad40072475956
sha256: 9438638a6962ac39926b3d5dbe88a59bd5cfccf4518d54371994fb92973f0cdb
sha512: a90587c770ff40701135ea9d0e2bd386821dca4bb5046f18d7ca6d849aa86f2d359a5d608b06f356ad4f4add819c4d9049f8638e176e9e57045fe9a2639f5d59
ssdeep: 48:6heXLJmTctNPGCvLHmCyYLp8y+f/UzEVnQBG/RACalGUCboDP:QwmYtPvLGa2yg/wAnQWRRUgq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FC1C7166FE848F5FAE70F3048F7498AAB70382217118EFF55770297589B8D5CC25B46
sha3_384: 22c2c0a5171f8799557b9b03a5bda1353009d5c95dac74136c993a1783af04bb391d504f02676af7ac79f365b04c7321
ep_bytes: 81ec3408000053555633f65756897424
timestamp: 2014-05-20 11:56:59

Version Info:

0: [No Data]

VHO:Trojan.Win32.Tremp also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.2153afaf9815c1af
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeDownloader-FBVU!2153AFAF9815
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.f9815c
VirITTrojan.Win32.DownLoad3.BXDO
CyrenW32/S-c6de9da2!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.E
APEXMalicious
KasperskyVHO:Trojan.Win32.Tremp.gen
BitDefenderGen:Heur.Mint.Gubbins.19
NANO-AntivirusTrojan.Win32.DownLoad3.etkgmw
MicroWorld-eScanGen:Heur.Mint.Gubbins.19
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10ce4d71
Ad-AwareGen:Heur.Mint.Gubbins.19
EmsisoftGen:Heur.Mint.Gubbins.19 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.ADW@8mzp93
DrWebTrojan.DownLoad3.33216
VIPRETrojan.Win32.Upatre.dw (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.zz
SophosML/PE-A + Mal/EncPk-ACO
IkarusTrojan-Downloader.Win32.Upatre
GDataGen:Heur.Mint.Gubbins.19
JiangminTrojanSpy.Zbot.ffhh
AviraHEUR/AGEN.1102633
Antiy-AVLTrojan/Generic.ASMalwS.2242F6F
ArcabitTrojan.Mint.Gubbins.19
MicrosoftTrojan:Win32/zbot.ffhh!MTB
AhnLab-V3Trojan/Win32.Upatre.C3469083
Acronissuspicious
VBA32SScope.Trojan-Downloader.1454
ALYacGen:Heur.Mint.Gubbins.19
MAXmalware (ai score=87)
MalwarebytesMalware.AI.654066645
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDropper.Generic!8.35E (TFE:dGZlOgPvXYFLswvyKQ)
YandexTrojan.GenAsa!zfalv5UzsQI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/EncPk.ACO!tr
BitDefenderThetaAI:Packer.C726C7E31F
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove VHO:Trojan.Win32.Tremp?

VHO:Trojan.Win32.Tremp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment