Malware

PWS:Win32/Wowsteal.ZF removal

Malware Removal

The PWS:Win32/Wowsteal.ZF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Wowsteal.ZF virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with NsPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PWS:Win32/Wowsteal.ZF?


File Info:

name: 877D1AA52F65C2E42014.mlw
path: /opt/CAPEv2/storage/binaries/08933e5dfe5ebc0dac472df3dd1dccaa80acfc0dabbcd35f487d7140194ec6ec
crc32: 26493D65
md5: 877d1aa52f65c2e42014d1466e5bf6e8
sha1: 14a86de589c361bd1e6e046535625c6fcb166e58
sha256: 08933e5dfe5ebc0dac472df3dd1dccaa80acfc0dabbcd35f487d7140194ec6ec
sha512: ef80ed0cae010c1cbb67ef9d47842354190c95d7cd23b5594369328d515915aef40859c9d021ba3804b115dfe612bb2d4510a9ad57d6645b26584c721da57e1c
ssdeep: 3072:cc+TRPB7Dx/KBAMWt7grFg+erm2rwtYr97Isns9gE/OZE0/KwB2TFcKPEqKaKS:BePBE+tuFg+evSsm/0hEPHKaK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12344E61BB382B22AC456C4F16BBA167824AEEEB100ED581FEB037B1439E1DD645D07D7
sha3_384: 4e0d9be4e3ace707ba93edc5ace57539a18811e58bd7bf61ecf4494dfd4d21bfa682e54adcac542e5724c8b303d0bd55
ep_bytes: 9c60e8000000005d83ed078d9d9ffeff
timestamp: 2006-07-24 01:30:38

Version Info:

Translation: 0x0804 0x04b0
CompanyName: W54L7EKdk
ProductName: W54L7EKdk
FileVersion: 0.00.0085
ProductVersion: 0.00.0085
InternalName: W54L7EKdk
OriginalFilename: W54L7EKdk.exe

PWS:Win32/Wowsteal.ZF also known as:

BkavW32.AIDetectNet.01
LionicWorm.Win32.Fujack.lhIR
MicroWorld-eScanGen:Variant.Graftor.976817
FireEyeGeneric.mg.877d1aa52f65c2e4
ALYacGen:Variant.Graftor.976817
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005257651 )
K7AntiVirusTrojan ( 005257651 )
BitDefenderThetaGen:NN.ZexaF.36132.qmuaauDHp4cb
CyrenW32/VisualBasicMalware!Eldorado
SymantecInfostealer.Lemir
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.PSW.OnlineGames.BP
APEXMalicious
ClamAVWin.Trojan.Lmir-9779990-0
BitDefenderGen:Variant.Graftor.976817
NANO-AntivirusTrojan.Win32.Wow.vsabk
AvastWin32:Lmir-DZ [Trj]
TencentWin32.Trojan.Crypt.Szfl
EmsisoftGen:Variant.Graftor.976817 (B)
BaiduWin32.Trojan-PSW.ZhengTu.a
F-SecureTrojan.TR/Crypt.NSPM.Gen
DrWebBackDoor.Generic.1391
VIPREGen:Variant.Graftor.976817
TrendMicroTROJ_GEN.R067C0DD423
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dm
Trapminemalicious.high.ml.score
SophosMal/GamePSW-C
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.976817
JiangminTrojan/PSW.GamePass.eq
GoogleDetected
AviraTR/Crypt.NSPM.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[GameThief]/Win32.Lmir
XcitiumPacked.Win32.MNSP.Gen@2697wr
ArcabitTrojan.Graftor.DEE7B1
MicrosoftPWS:Win32/Wowsteal.ZF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Lmirhack.C90983
Acronissuspicious
McAfeeArtemis!877D1AA52F65
VBA32TrojanPSW.Lmir
Cylanceunsafe
PandaTrj/Legmir.AAM
ZonerProbably Heur.ExeHeaderP
TrendMicro-HouseCallTROJ_GEN.R067C0DD423
RisingTrojan.Win32.Generic.15A7CE98 (C64:YzY0OvyuDsx5GXA1)
YandexTrojan.GenAsa!HAh8NOWsDx8
IkarusTrojan-PWS.Win32.Lmir.axg
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Lmir.APIT!tr
AVGWin32:Lmir-DZ [Trj]
DeepInstinctMALICIOUS

How to remove PWS:Win32/Wowsteal.ZF?

PWS:Win32/Wowsteal.ZF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment