Worm

Win32.Worm.SoulClose.E (B) removal instruction

Malware Removal

The Win32.Worm.SoulClose.E (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.SoulClose.E (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Win32.Worm.SoulClose.E (B)?


File Info:

name: A0F908D995EEEC27DD18.mlw
path: /opt/CAPEv2/storage/binaries/9f5889c955853d9107927aa5b20fc8cd8d2dd727511ec69a8c32eb85bb80391f
crc32: F31600E6
md5: a0f908d995eeec27dd189235defd812c
sha1: 658ff9dec62eda4ce5312836934d7f54fc168f59
sha256: 9f5889c955853d9107927aa5b20fc8cd8d2dd727511ec69a8c32eb85bb80391f
sha512: 61a84a9eb7854047620d412d35d550ff68cd1a724e43e9060a955a8a46d4a805d154d7b774718273165b2f7c78691484ea21d61bbdaa4a8dfb70f2780dffaecf
ssdeep: 12288:y8QcfX8QcflaYeiveC8omNZHsyClgmw6zxV7L:UcFcDw/r6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194F40822B555E02ED4A64AF59929CBF96838AF611E50ACD37BC03F5D3F71983D02132B
sha3_384: 59fc710680c76ec8dbf5489a7637078afb70943a1050ccce124dc7a7e190b3f16c56afccbf8c3110c9a177a8e512fe8d
ep_bytes: 68488f4000e8f0ffffff000000000000
timestamp: 2008-06-08 14:36:24

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 2146
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: avp
OriginalFilename: avp.exe

Win32.Worm.SoulClose.E (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.SoulClose.E
ALYacWin32.Worm.SoulClose.E
CylanceUnsafe
ZillyaWorm.VB.Win32.481
SangforTrojan.Win32.Save.a
K7AntiVirusP2PWorm ( 004e419d1 )
K7GWP2PWorm ( 004e419d1 )
Cybereasonmalicious.995eee
BaiduWin32.Worm.VB.bc
CyrenW32/Worm.Soul.gen!Eldorado
SymantecW32.Fujacks.C
ESET-NOD32a variant of Win32/AutoRun.VB.HG
APEXMalicious
ClamAVWin.Worm.Soulclose-7085422-0
KasperskyWorm.Win32.VB.rc
BitDefenderWin32.Worm.SoulClose.E
NANO-AntivirusTrojan.Win32.VB.ooto
AvastWin32:VB-JHS [Wrm]
TencentMalware.Win32.Gencirc.114b9994
Ad-AwareWin32.Worm.SoulClose.E
SophosML/PE-A + W32/OYSoul-Gen
ComodoVirus.Win32.VB.~A@ziv7
DrWebWin32.HLLW.Autoruner.2173
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.bm
FireEyeGeneric.mg.a0f908d995eeec27
EmsisoftWin32.Worm.SoulClose.E (B)
IkarusVirus.Worm.Win32.VB
GDataWin32.Worm.SoulClose.E
JiangminWorm/VB.pcu
AviraTR/VB.dek.2
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.128E01C
ArcabitWin32.Worm.SoulClose.E
MicrosoftWorm:Win32/Soulclose.B
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VB.R287861
McAfeeArtemis!A0F908D995EE
YandexWorm.VB!R9/ixfALmfo
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/VB.MJU!tr
BitDefenderThetaAI:Packer.C7A6EBF020
AVGWin32:VB-JHS [Wrm]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32.Worm.SoulClose.E (B)?

Win32.Worm.SoulClose.E (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment