Malware

Win32/Vools.A removal tips

Malware Removal

The Win32/Vools.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Vools.A virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (194 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • A process sent information about the computer to a remote location.
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

log.weonc.com
log.oiwcvbnc2e.stream

How to determine Win32/Vools.A?


File Info:

crc32: DFD9A164
md5: ce436e0d954df61b1328ece8b245199c
name: CE436E0D954DF61B1328ECE8B245199C.mlw
sha1: b72d193c9812baeb5c6d0f862edddc0e7f3f6cf5
sha256: 572db3f9a2fa4cd81701540e03ab048b0b759c0b7e6b2717125509cb8b6496f5
sha512: 1870cc0c666d93e59d9e4b23573fd76dd79d801baf8b1f5e1927828f2fb6ecd838d4e636b09cec1b99ab845c91bd2abdabf20dc8558c434249462a3f692acba2
ssdeep: 6144:vV2aTVYVR1eKk1ExKxB0vflBlPESPPIj2um6w55pZjpfCVfdUc08k08pG4:kaTVWfXkXKlBQtq55pZjpfCj+HZ
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Vools.A also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005246331 )
Elasticmalicious (high confidence)
DrWebTrojan.Vools.7
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GenericKD.30356003
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39685
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.85677806
K7GWTrojan ( 005246331 )
Cybereasonmalicious.d954df
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Vools.A
APEXMalicious
AvastWin32:Agent-ATYH [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.krfe
BitDefenderTrojan.Ransom.GenericKD.30356003
NANO-AntivirusTrojan.Win32.Blocker.eyekhk
MicroWorld-eScanTrojan.Ransom.GenericKD.30356003
TencentWin32.Trojan.Blocker.Taet
Ad-AwareTrojan.Ransom.GenericKD.30356003
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34790.tqW@a0vAbtk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_WMINE.SM
McAfee-GW-EditionBehavesLike.Win32.Injector.fh
FireEyeGeneric.mg.ce436e0d954df61b
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.ifc
AviraTR/Blocker.zwtql
Antiy-AVLTrojan/Generic.ASMalwS.24840E7
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmTrojan-Ransom.Win32.Blocker.krfe
GDataTrojan.Ransom.GenericKD.30356003
TACHYONRansom/W32.Blocker.322560
AhnLab-V3Trojan/Win32.Blocker.C2393872
McAfeeGenericRXEG-OO!CE436E0D954D
MAXmalware (ai score=96)
VBA32BScope.Backdoor.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_WMINE.SM
RisingTrojan.Generic@ML.92 (RDML:lBLEFQTMvKJrxED9H8ZW9Q)
YandexTrojan.GenAsa!RIKqtA80l+o
IkarusTrojan.Win32.Vools
FortinetW32/Generic.AC.407424
AVGWin32:Agent-ATYH [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwoCEpsA

How to remove Win32/Vools.A?

Win32/Vools.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment