Trojan

Trojan.Win32.Wofith.ecb removal

Malware Removal

The Trojan.Win32.Wofith.ecb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Wofith.ecb virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A potential decoy document was displayed to the user
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

www.bing.com
ocsp.digicert.com
g2.symcb.com
vassg142.ocsp.omniroot.com

How to determine Trojan.Win32.Wofith.ecb?


File Info:

crc32: 4750FADB
md5: 4e0aa4ac89b2a33c519ab57dea2aead2
name: 4E0AA4AC89B2A33C519AB57DEA2AEAD2.mlw
sha1: edda53d9152a46c5885a30f5db8927fa860ea8be
sha256: 29a9b540dd1466e808dbfc8b18e5f8618eb1548f9d75ffb22d735294bd393461
sha512: 7c1e796f2feac0d612553af1fe680aef2869ce877a6276a1a2b8d51268f0523044ccd7aaac3273e80e5b5d5d6677c7641aecd66bd348bb9c297e3fdb39546f1d
ssdeep: 1536:cGRVCaKgzbLc54hukfgvenL2ABV1Ayj4m/QWR/Rlq88vlnRqPR/1aViDRknJM2S6:cGjbLl/gv+L2Av1Tj4mYWR/R4nkPR/1a
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Win32.Wofith.ecb also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70387
FireEyeGeneric.mg.4e0aa4ac89b2a33c
ALYacTrojan.GenericKDZ.70387
CylanceUnsafe
VIPREWorm.Win32.Agent.cp (v)
SangforMalware
K7AntiVirusTrojan ( 0051918e1 )
BitDefenderTrojan.GenericKDZ.70387
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.c89b2a
TrendMicroTROJ_GEN.R002C0CKI20
BaiduWin32.Worm.Agent.fj
CyrenW32/Agent.BUP.gen!Eldorado
SymantecW32.SillyWNSE
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.D46e2dc-6911509-0
KasperskyTrojan.Win32.Wofith.ecb
AlibabaTrojan:Win32/Starter.ali1001008
NANO-AntivirusTrojan.Win32.Wofith.hzygna
AegisLabWorm.Win32.Generic.o!c
AvastWin32:Evo-gen [Susp]
RisingWorm.Agent!1.BDD2 (TFE:1:D9WfLPr77jM)
Ad-AwareTrojan.GenericKDZ.70387
SophosTroj/Agent-BFWE
ComodoWorm.Win32.Agent.CP@42tt
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.MulDrop15.57947
InvinceaML/PE-A + Troj/Agent-BFWE
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
MaxSecureTrojan.Malware.300983.susgen
EmsisoftTrojan.GenericKDZ.70387 (B)
IkarusWorm.Win32.Agent
JiangminWorm.Agent.ws
AviraTR/Crypt.ULPM.Gen
Antiy-AVLGrayWare/Win32.Agent.CP
MicrosoftWorm:Win32/Sfone
GridinsoftTrojan.Heur!.032120A9
ArcabitTrojan.Generic.D112F3
ZoneAlarmTrojan.Win32.Wofith.ecb
GDataTrojan.GenericKDZ.70387
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Agent.R234001
Acronissuspicious
McAfeeGenericRXAA-AA!4E0AA4AC89B2
MAXmalware (ai score=81)
VBA32Worm.Agent
ESET-NOD32a variant of Win32/Agent.CP
TrendMicro-HouseCallTROJ_GEN.R002C0CKI20
TencentMalware.Win32.Gencirc.10cdccdf
YandexTrojan.GenAsa!yTn6LLlAQA4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Agent.6C6A!tr
BitDefenderThetaAI:Packer.359218931E
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Worm.Sfone.A

How to remove Trojan.Win32.Wofith.ecb?

Trojan.Win32.Wofith.ecb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment