Trojan

What is “Trojan.Win32.Wofith.hka”?

Malware Removal

The Trojan.Win32.Wofith.hka is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Wofith.hka virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Wofith.hka?


File Info:

name: 040E6EA8A862DC5DEBC9.mlw
path: /opt/CAPEv2/storage/binaries/d93d4cf48ab9bf189b56775eb48500fd539e3b83174fd538fbde4aa2459d66a3
crc32: 235841D5
md5: 040e6ea8a862dc5debc96095f49b3209
sha1: 47f94537150c9deb38e8e2474ec3a6a2d5a55f34
sha256: d93d4cf48ab9bf189b56775eb48500fd539e3b83174fd538fbde4aa2459d66a3
sha512: f005c8022b855c70778bf0cc1b7d1253ade67bc67455911fab3b2c9231d1c2d0a6c12e4094ad3d3a000d4791a3bef5bdc6b467591cb3a538ca0dae3c319df4cb
ssdeep: 3072:Vq9fTF+DQYA6cUfAbAakXNHtOLuL1bfo/ibOXvVHygqcxGpR7d/:s9fOHA6cUI0akVtsulfXdl
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T11C343A597764C0E6E17A9134C81696B5F272BC21C7209ADF06A03B7ABF336D06C3E719
sha3_384: 399935f4e99c6561ab246d94dc9ec80a25fc2b307df28bc22ba927cd61f14a319bf4b4f6fda0681929e7994a0465308f
ep_bytes: 4883ec28e8a70400004883c428e97afe
timestamp: 2021-12-09 01:20:57

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0
InternalName: 加入任务计划
LegalCopyright: (C) 版权所有
OriginalFilename: 加入任务计划.exe
ProductName:
ProductVersion: 1.0
Translation: 0x0804 0x04b0

Trojan.Win32.Wofith.hka also known as:

LionicTrojan.Win32.Wofith.4!c
FireEyeTrojan.GenericKD.38300407
ALYacTrojan.GenericKD.38300407
CylanceUnsafe
ZillyaTrojan.Wofith.Win32.303
AlibabaTrojan:Win32/Wofith.9ca14220
ArcabitTrojan.Generic.D2486AF7
SymantecTrojan.Gen.2
APEXMalicious
KasperskyTrojan.Win32.Wofith.hka
BitDefenderTrojan.GenericKD.38300407
MicroWorld-eScanTrojan.GenericKD.38300407
AvastWin64:TrojanX-gen [Trj]
TencentWin32.Trojan.Wofith.Bny
Ad-AwareTrojan.GenericKD.38300407
EmsisoftTrojan.GenericKD.38300407 (B)
McAfee-GW-EditionArtemis
SophosMal/Generic-S
JiangminTrojan.Wofith.do
GridinsoftRansom.Win64.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
GDataTrojan.GenericKD.38300407
McAfeeArtemis!040E6EA8A862
MAXmalware (ai score=84)
VBA32Trojan.Bsymem
TrendMicro-HouseCallTROJ_GEN.R002H07LL21
YandexTrojan.Wofith!0KjFPaV8yyM
FortinetW32/PossibleThreat
AVGWin64:TrojanX-gen [Trj]

How to remove Trojan.Win32.Wofith.hka?

Trojan.Win32.Wofith.hka removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment