Trojan

Trojan.WebToos information

Malware Removal

The Trojan.WebToos is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Trojan.WebToos virus can do?

  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.WebToos?


File Info:

crc32: 4FE315EA
md5: 597f01ce02ebeffe9c9b4a066bdbfbb3
name: 597F01CE02EBEFFE9C9B4A066BDBFBB3.mlw
sha1: ed2ae0c0c8f71b30842b9febf06a26172c66aa7d
sha256: 3b2cf351142e7a5b36f1c1c9850e797fd7ffe01cc017159022ef83d5118cf4bd
sha512: 2df507006f00e8071b30d7714cc9d954bd273b267748b700ae6835ac464b56179f6ae03144774b444b3bc2e9a71a8f3b4bf12b4e4ea11a0eeac8aa73c9c7812a
ssdeep: 24576:UZUwXfHfdrWqVn6tnFE2A8ZF6Qm+pKVGH9fcwDLMQG+i2XlR:Cf/RCGmdpKe9fc1F2f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.WebToos also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRootKit ( 0055e3fe1 )
LionicTrojan.Win32.Reconyc.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Gates.8
CynetMalicious (score: 100)
CAT-QuickHealTrojan.WebToos.S18562
ALYacTrojan.Agent.CGMR
CylanceUnsafe
ZillyaRootkit.Agent.Win32.15968
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/WebToos.259f4225
K7GWRootKit ( 0055e3fe1 )
Cybereasonmalicious.e02ebe
BaiduWin32.Rootkit.Agent.at
CyrenW32/WebToos.B.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Prockill-A [Rtk]
ClamAVWin.Trojan.Gadoopt-2
KasperskyTrojan.Win32.Reconyc.esql
BitDefenderTrojan.Agent.CGMR
NANO-AntivirusTrojan.Win32.Reconyc.exhhog
ViRobotBackdoor.Win32.Agent.1315840.A
MicroWorld-eScanTrojan.Agent.CGMR
TencentMalware.Win32.Gencirc.10b54e8b
Ad-AwareTrojan.Agent.CGMR
SophosMal/Generic-R
ComodoMalware@#1yy5f49lzwybj
BitDefenderThetaGen:NN.ZexaF.34170.puW@aKX7Duki
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_WEBTOOS.SM
McAfee-GW-EditionBehavesLike.Win32.Emotet.th
FireEyeGeneric.mg.597f01ce02ebeffe
EmsisoftTrojan.Agent.CGMR (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Reconyc.eyd
WebrootW32.Trojan.Gadoopt-1
AviraTR/Agent.14016.2
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.A3CBB3
KingsoftWin32.Troj.Reconyc.es.(kcloud)
MicrosoftTrojan:Win32/WebToos.A
GridinsoftRootkit.Win32.Agent.bot!s1
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
ZoneAlarmTrojan.Win32.Reconyc.esql
GDataTrojan.Agent.CGMR
TACHYONTrojan/W32.Rootkit.1315840
AhnLab-V3Trojan/Win32.Webtoos.C1040590
McAfeeGenericRXDY-OY!597F01CE02EB
MAXmalware (ai score=84)
VBA32Backdoor.Gates
MalwarebytesTrojan.WebToos
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_WEBTOOS.SM
RisingTrojan.Gadoopt/x64!1.A7DF (CLASSIC)
YandexTrojan.GenAsa!84t1QyHA9Mc
IkarusBackdoor.Win32.Agent
FortinetW32/Agent.DGUG!tr
AVGWin32:Prockill-A [Rtk]
Paloaltogeneric.ml

How to remove Trojan.WebToos?

Trojan.WebToos removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment