Trojan

How to remove “Trojan.Win32.Wofith.ede”?

Malware Removal

The Trojan.Win32.Wofith.ede is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Wofith.ede virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

www.bing.com
crl3.digicert.com
ocsp.digicert.com

How to determine Trojan.Win32.Wofith.ede?


File Info:

crc32: 4FD7ECA5
md5: 144721cfcd0e1eea0c5b756d4d60d37d
name: 144721CFCD0E1EEA0C5B756D4D60D37D.mlw
sha1: 6c8c38b06bf7ffe4d9536fc15f7bdc92a750c7f1
sha256: e92d8dba4086ce68a0fae2033e4abb28a4b29cdd7f2b438c7153c2ca481956b1
sha512: 5af0fd8e6290f45fd158ffd5eadaa7b45d770777ec7e53703e8c26dd6f76d7ccfd56a779bf86403281b518ab7085a1f9f7eee7644409613db4aa9a419d102f3d
ssdeep: 3072:cGjbLl/gvRgFdUQ1Tj4mYWR/R4nkPR/1aVuyJNyBR8Cng9+LriunysIjAv:xjluRgYSIo5R4nM/40yJNyBR8AISKI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Win32.Wofith.ede also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70387
FireEyeGeneric.mg.144721cfcd0e1eea
CAT-QuickHealTrojan.Wofith
McAfeeGenericRXAA-AA!144721CFCD0E
CylanceUnsafe
VIPREWorm.Win32.Agent.cp (v)
AegisLabTrojan.Win32.Rbot.l3oz
SangforMalware
K7AntiVirusTrojan ( 0051918e1 )
BitDefenderTrojan.GenericKDZ.70387
K7GWTrojan ( 0051918e1 )
CrowdStrikewin/malicious_confidence_100% (D)
TrendMicroTROJ_GEN.R06EC0CKI20
BaiduWin32.Worm.Agent.fj
CyrenW32/Agent.BUP.gen!Eldorado
SymantecW32.SillyWNSE
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.D46e2dc-6911509-0
KasperskyTrojan.Win32.Wofith.ede
AlibabaTrojan:Win32/Starter.ali1001008
NANO-AntivirusTrojan.Win32.Wofith.hzygna
TencentMalware.Win32.Gencirc.10cdccdf
Ad-AwareTrojan.GenericKDZ.70387
SophosTroj/Agent-BFWE
ComodoMalware@#14mralq4dml0v
F-SecureWorm.WORM/Rbot.Gen
DrWebTrojan.MulDrop15.57947
InvinceaML/PE-A + Troj/Agent-BFWE
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftTrojan.GenericKDZ.70387 (B)
IkarusWorm.Win32.Agent
JiangminWorm.Agent.ws
AviraWORM/Rbot.Gen
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.Agent.cp
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftWorm:Win32/Sfone
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Generic.D112F3
ZoneAlarmTrojan.Win32.Wofith.ede
GDataTrojan.GenericKDZ.70387
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Agent.R234001
Acronissuspicious
BitDefenderThetaAI:Packer.FE0655941E
ALYacTrojan.GenericKDZ.70387
VBA32Worm.Agent
MalwarebytesWorm.Agent
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Agent.CP
TrendMicro-HouseCallTROJ_GEN.R06EC0CKI20
RisingWorm.Agent!1.BDD2 (TFE:1:D9WfLPr77jM)
YandexTrojan.GenAsa!yTn6LLlAQA4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Agent.6C6A!tr
WebrootW32.Trojan.Gen
AVGFileRepMalware
Cybereasonmalicious.fcd0e1
Paloaltogeneric.ml
Qihoo-360Win32/Worm.Sfone.A

How to remove Trojan.Win32.Wofith.ede?

Trojan.Win32.Wofith.ede removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment