Malware

Should I remove “Win32/Woool.E”?

Malware Removal

The Win32/Woool.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Woool.E virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Checks for the presence of known windows from debuggers and forensic tools

Related domains:

z.whorecord.xyz
a.tomx.xyz
fhdlq.oss-cn-beijing.aliyuncs.com
ocsp.globalsign.com
ocsp2.globalsign.com
a.75cs.com
wd.gaochuanshi.com
www.wtaoche.com
b.75cs.com

How to determine Win32/Woool.E?


File Info:

crc32: 9E2E6BD4
md5: 1f4c285dbf6967b4dac9148804755774
name: 1F4C285DBF6967B4DAC9148804755774.mlw
sha1: 601273f3ab69029a9232011852f6c557926c6403
sha256: 9b31dc0385a4fdf0a180676c070e94e15afcbb88baeddb88a8faeb273697cc6b
sha512: abafea0b18f7b1d737c9ac0dccc7e73e039b811eed587b88780b2d6f4c7c28e0fae01799477d773f8f433ccd0160a7fa9801759a0a6ebe815d9dda8bbac0e9dd
ssdeep: 98304:fK5BamyIF9r3Qnqg2DZk7NYEAiiLv11a9anlT8QViip:CTauZbINYEAiiB1288QViip
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: x3000
FileVersion: 1.1.0.0
CompanyName:
LegalTrademarks:
Comments: x51e4x51f0x5de5x4f5cx5ba4x8363x8a89x51fax54c1
ProductName: x51e4x51f0x767bx9646x5668
ProductVersion: Pnoenixerx3000
FileDescription: x3000
OriginalFilename:
Translation: 0x0804 0x03a8

Win32/Woool.E also known as:

K7AntiVirusTrojan ( 004f01851 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.32856
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.34688720
CylanceUnsafe
ZillyaTrojan.Woool.Win32.442
SangforTrojan.Win32.Agent.nil
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaMalware:Win32/km_2b07fd.None
K7GWTrojan ( 004f01851 )
Cybereasonmalicious.dbf696
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Woool.E
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan-GameThief.Win32.OnLineGames.aliqm
BitDefenderTrojan.GenericKD.34688720
NANO-AntivirusTrojan.Win32.OnLineGames.hysldi
MicroWorld-eScanTrojan.GenericKD.34688720
TencentWin32.Trojan-gamethief.Onlinegames.Eaee
Ad-AwareTrojan.GenericKD.34688720
SophosMal/Generic-S
ComodoMalware@#nb4non1mb0ju
BitDefenderThetaGen:NN.ZexaF.34266.@V3@auzeiSkb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.rc
FireEyeGeneric.mg.1f4c285dbf6967b4
EmsisoftTrojan.GenericKD.34688720 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1138598
MicrosoftTrojan:Win32/Tnega!ml
ArcabitTrojan.Generic.D2114ED0
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.aliqm
GDataTrojan.GenericKD.34688720
AhnLab-V3Malware/Win32.RL_Generic.R354143
Acronissuspicious
McAfeeArtemis!1F4C285DBF69
MAXmalware (ai score=82)
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:lmXjoSy+r+H2povrNA4muw)
YandexTrojan.Woool!RUJTf6MJYlc
IkarusTrojan.Win32.Woool
MaxSecureTrojan.Malware.8069.susgen
FortinetW32/Woool.C!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Win32/Woool.E?

Win32/Woool.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment