Trojan

TrojanDownloader:Win32/Wysotot.A removal guide

Malware Removal

The TrojanDownloader:Win32/Wysotot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Wysotot.A virus can do?

  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

xa.xingcloud.com
www.twonext.com
www.goplayer.cc
ww1.goplayer.cc

How to determine TrojanDownloader:Win32/Wysotot.A?


File Info:

crc32: 29A435DB
md5: 5d886c9575af88e542bb9a0b5d3c072d
name: 5D886C9575AF88E542BB9A0B5D3C072D.mlw
sha1: 6deaf303e6ccb9b98519ffe0cd2c161907d33bbd
sha256: bc872e44afc442cd13bdad826a729a19526a633d185e0502606c21d05c9484b3
sha512: cff3d047621d6b92727db6f8635fa4b1ce92377f7d390f8d70f28c876ff02b51519c530ab1d0103a182ce8ef86399f3bc507658fa6db8265d5727784cc360499
ssdeep: 3072:PnvoDlfy0y+QbD5rwWT1Jx6o+zWsp7DuwXkS4:/AB369X1JsogoS54
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013
InternalName: iXB.exe
FileVersion: 2.0.0.23
OriginalFilename: iXB.exe
ProductVersion: 2.0.0.23
Translation: 0x0409 0x04b0

TrojanDownloader:Win32/Wysotot.A also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.ExqPage.J
FireEyeGeneric.mg.5d886c9575af88e5
ALYacApplication.ExqPage.J
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.AdLoad.1!c
SangforMalware
K7AntiVirusAdware ( 0050fb521 )
BitDefenderApplication.ExqPage.J
K7GWAdware ( 0050fb521 )
Cybereasonmalicious.575af8
CyrenW32/Startpage.CA.gen!Eldorado
SymantecDownload.Adware
APEXMalicious
AvastWin32:Wysotot-F [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.AdLoad.qxnx
AlibabaTrojanDownloader:Win32/Wysotot.c7096cfd
NANO-AntivirusTrojan.Win32.Badur.cqkyto
TencentMalware.Win32.Gencirc.10c03d25
Ad-AwareApplication.ExqPage.J
SophosGeneric PUA GN (PUA)
ComodoTrojWare.Win32.TrojanDownloader.Agent.HDTD@57smdi
F-SecureAdware.ADWARE/Adware.Gen2
DrWebAdware.Elex.2
ZillyaDownloader.Adload.Win32.20402
TrendMicroTROJ_GEN.R002C0DLM20
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftApplication.ExqPage.J (B)
JiangminTrojan/StartPage.osk
AviraADWARE/Adware.Gen2
Antiy-AVLTrojan/Win32.StartPage
MicrosoftTrojanDownloader:Win32/Wysotot.A
ArcabitApplication.ExqPage.J
ZoneAlarmnot-a-virus:Downloader.Win32.AdLoad.qxnx
GDataWin32.Trojan.ExqWilsys.E
McAfeeArtemis!5D886C9575AF
MAXmalware (ai score=72)
VBA32Trojan.StartPage
MalwarebytesPUP.Optional.Elex
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.ELEX.PL
TrendMicro-HouseCallTROJ_GEN.R002C0DLM20
RisingDownloader.Wysotot!8.D54 (CLOUD)
YandexTrojan.GenAsa!hHGsm08CC70
SentinelOneStatic AI – Malicious PE – Adware
FortinetRiskware/Elex
BitDefenderThetaGen:NN.ZexaF.34804.ou1@aOf4Emcj
AVGWin32:Wysotot-F [Adw]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Virus.Downloader.bd6

How to remove TrojanDownloader:Win32/Wysotot.A?

TrojanDownloader:Win32/Wysotot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment