Trojan

Trojan:Win32/Wrokni.C (file analysis)

Malware Removal

The Trojan:Win32/Wrokni.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Wrokni.C virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs an hook procedure to monitor for mouse events
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to disable Windows Defender
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
05779b0d24fb315d.xyz
a.tomx.xyz

How to determine Trojan:Win32/Wrokni.C?


File Info:

crc32: 62244D76
md5: d720410f90506ef25b01f0b5f9232511
name: y3.exe
sha1: 276667bb262eb8728c4571b27bb1b10b6ed7f473
sha256: eecf953dc560f19a04004286f0765ca33a6271bc81da5a96ba06da3daacff472
sha512: fcf3ef4c08fffe04726ae0963ee94b6c3cd9092a18c522184cc015e6b2a4bb44330c48ca497150f972fb7e1e6c9b47fc00295be218c5dc67f4b6090980792caf
ssdeep: 49152:hzMiE/7fPXsOs1rj9RTs9oapdzxdd6XG+cFf+A2mYeK:6HXwk+AhOcF5yeK
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, MS CAB-Installer self-extracting archive

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 1981-1997
InternalName: Wextract
FileVersion: 4.72.3110.0
CompanyName: Microsoft Corporation
ProductName: Sistema operativo Microsoft(R) Windows NT(R)
ProductVersion: 4.72.3110.0
FileDescription: Programma di autoestrazione di file CAB Win32
OriginalFilename: WEXTRACT.EXE
Translation: 0x0410 0x04b0

Trojan:Win32/Wrokni.C also known as:

DrWebTrojan.Siggen9.45108
MicroWorld-eScanAdware.GenericKD.33810412
FireEyeGeneric.mg.d720410f90506ef2
McAfeeArtemis!D720410F9050
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderAdware.GenericKD.33810412
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b262eb
GDataAdware.GenericKD.33810412
KasperskyTrojan.Win32.Injects.szd
AlibabaAdWare:Win32/Zdengo.a3ccdaf9
Ad-AwareAdware.GenericKD.33810412
EmsisoftAdware.GenericKD.33810412 (B)
F-SecureAdware.ADWARE/Zdengo.tkpnw
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SophosGeneric PUA CH (PUA)
IkarusTrojan.VBCrypt
CyrenW32/Trojan.KYRA-7879
AviraADWARE/Zdengo.tkpnw
ArcabitAdware.Generic.D203E7EC
ZoneAlarmTrojan.Win32.Injects.szd
MicrosoftTrojan:Win32/Wrokni.C
Acronissuspicious
ALYacAdware.GenericKD.33810412
MAXmalware (ai score=87)
MalwarebytesAdware.Zdengo
PandaTrj/CI.A
ESET-NOD32Win32/Adware.Zdengo.EWM
TrendMicro-HouseCallTROJ_GEN.R002H07EA20
TencentWin32.Trojan.Injects.Wpsq
FortinetW32/GenKryptik.EHWD!tr
AVGFileRepMetagen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Generic/Virus.Adware.409

How to remove Trojan:Win32/Wrokni.C?

Trojan:Win32/Wrokni.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment