Trojan

Trojan:Win32/Woozlist.B removal tips

Malware Removal

The Trojan:Win32/Woozlist.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Woozlist.B virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Woozlist.B?


File Info:

name: 267E525D49FC99A4FE48.mlw
path: /opt/CAPEv2/storage/binaries/3fed6ec491ed7406fd50e1c9a3be4ae006ef8d77691ba057fbf16db21a940cbc
crc32: 5500D69E
md5: 267e525d49fc99a4fe484717822ef233
sha1: 790a572571f842ea99e376d6c23a86b1ba2501af
sha256: 3fed6ec491ed7406fd50e1c9a3be4ae006ef8d77691ba057fbf16db21a940cbc
sha512: c43f4b9f9d246ac1ae0606d239345361946efec2f7bd229d01883ee82c368f9363af0cd5770ccef018ecb26ba0ee055133f28b8a8157bf6e8d2d48593f2e18c0
ssdeep: 12288:vq5uJX+8fZZHYWbymdVZddaohbM33UicEgGuJhlVQLAG3tu:voJ8RZ4WzdVZddaohQUicrGuJqkG3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A426327ECF69CC70F5176630964EDD2CB072AF2468B081E412E63974C5B1386A5EDAE3
sha3_384: 6270017efedeaff73819bd3680eed1d4c8290d4691817069a199171f6f7c1de30799fa76f8ea8ee7a1198565864b02f0
ep_bytes: 558bec6aff6820f5850068b843470064
timestamp: 2011-04-05 19:08:59

Version Info:

FileVersion: 1.0.0.0
FileDescription: 红树林服务评价系统
ProductName: 红树林服务评价系统
ProductVersion: 1.0.0.0
CompanyName: 西安网吧运营中心
LegalCopyright: 西安网吧运营中心 版权所有
Comments: 红树林服务评价系统
Translation: 0x0804 0x04b0

Trojan:Win32/Woozlist.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.liRL
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.69822296
FireEyeGeneric.mg.267e525d49fc99a4
SkyhighBehavesLike.Win32.Generic.rt
McAfeeArtemis!267E525D49FC
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
ArcabitTrojan.Generic.D4296758
BitDefenderThetaGen:NN.ZexaF.36792.@t0@aihsm5iH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
BitDefenderTrojan.GenericKD.69822296
AvastWin32:TrojanX-gen [Trj]
EmsisoftTrojan.GenericKD.69822296 (B)
F-SecureTrojan:W32/DelfInject.R
VIPRETrojan.GenericKD.69822296
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
VaristW32/Trojan.CLL.gen!Eldorado
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.990
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Woozlist.B
GDataWin32.Trojan.PSE.15IBL0F
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5541696
VBA32BScope.Trojan.Reconyc
ALYacTrojan.GenericKD.69822296
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CJM23
RisingTrojan.Generic@AI.99 (RDML:NUjIzGKSpq8I6ZF+4tqAUw)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.571f84
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Woozlist.B?

Trojan:Win32/Woozlist.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment