In this post, I am going to clarify the way the Woreflint trojan infused into your PC, and also the best way to clear away Woreflint trojan virus.
What is Woreflint trojan?
Name | Woreflint |
Infection Type | Trojan |
Symptoms |
|
Similar behavior | Morila, ShWg, Emotet, Upatre, Lightaidra, Skeeyah |
Fix Tool | See If Your System Has Been Affected by Woreflint trojan |
Trojan viruses are one of the leading malware sorts by its injection rate for quite a very long time. And currently, throughout the pandemic, when malware became enormously active, trojan viruses increased their activity, too. You can see a lot of messages on diverse resources, where users are complaining about the Woreflint trojan virus in their computer systems, and requesting help with Woreflint trojan virus removal.
Trojan Woreflint is a kind of virus that injects right into your PC, and afterwards performs a wide range of harmful features. These functions depend on a sort of Woreflint trojan: it can function as a downloader for other malware or as a launcher for an additional harmful program which is downloaded together with the Woreflint trojan virus. During the last 2 years, trojans are additionally dispersed through e-mail add-ons, and in the majority of cases utilized for phishing or ransomware infiltration.
Woreflint2 also known as
Bkav | W32.AIDetectVM.malware1 |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Heur.Mint.SP.Azorult.1 |
FireEye | Generic.mg.327e61327c984e64 |
Cylance | Unsafe |
Sangfor | Malware |
BitDefender | Gen:Heur.Mint.SP.Azorult.1 |
Cybereason | malicious.27c984 |
Invincea | ML/PE-A |
BitDefenderTheta | Gen:NN.ZexaF.34570.qmW@a0wBzBn |
Symantec | ML.Attribute.HighConfidence |
APEX | Malicious |
F-Secure | Trojan.TR/Dropper.Gen |
McAfee-GW-Edition | BehavesLike.Win32.Generic.dh |
SentinelOne | DFI – Malicious PE |
Avira | TR/Dropper.Gen |
Antiy-AVL | GrayWare/Win32.Kryptik.ehls |
Microsoft | Trojan:Win32/Woreflint.A!cl |
Cynet | Malicious (score: 100) |
VBA32 | Malware-Cryptor.Bambarbiya |
Rising | Trojan.Crypto!8.364 (TFE:2:lGpISJAuUHN) |
Paloalto | generic.ml |
CrowdStrike | win/malicious_confidence_80% (D) |
Qihoo-360 | HEUR/QVM20.1.B6DB.Malware.Gen |
Domains that associated with Woreflint:
0 | z.whorecord.xyz |
1 | a.tomx.xyz |
2 | www.ip-adress.com |
What are the symptoms of Woreflint trojan?
- Executable code extraction;
- Injection (inter-process);
- Injection (Process Hollowing);
- Attempts to connect to a dead IP:Port (1 unique times);
- Creates RWX memory;
- Mimics the system’s user agent string for its own requests;
- Possible date expiration check, exits too soon after checking local time;
- A process attempted to delay the analysis task.;
- A named pipe was used for inter-process communication;
- Repeatedly searches for a not-found process, may want to run with startbrowser=1 option;
- A process created a hidden window;
- Performs some HTTP requests;
- The binary likely contains encrypted or compressed data.;
- Uses Windows utilities for basic functionality;
- Executed a process and injected code into it, probably while unpacking;
- A system process is generating network traffic likely as a result of process injection;
- Installs itself for autorun at Windows startup;
- Checks the CPU name from registry, possibly for anti-virtualization;
- Attempts to modify proxy settings;
- Collects information to fingerprint the system;
- Anomalous binary characteristics;
The frequent sign of the Woreflint trojan virus is a progressive appearance of various malware – adware, browser hijackers, and so on. Because of the activity of these destructive programs, your computer comes to be really sluggish: malware consumes large quantities of RAM and CPU capabilities.
One more visible effect of the Woreflint trojan virus visibility is unfamiliar processes showed in task manager. In some cases, these processes may try to simulate system processes, but you can understand that they are not legit by looking at the genesis of these processes. Pseudo system applications and Woreflint trojan’s processes are always specified as a user’s processes, not as a system’s.
How to remove Woreflint trojan virus?
- Download and install GridinSoft Anti-Malware.
- Open GridinSoft Anti-Malware and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Select proper browser and options – Click “Reset”.
- Restart your computer.
To remove Woreflint trojan and also be sure that all additional malware, downloaded with the help of this trojan, will certainly be removed, as well, I’d recommend you to use GridinSoft Anti-Malware.
Woreflint removal guide
To detect and eliminate all unwanted programs on your PC with GridinSoft Anti-Malware, it’s better utilize Standard or Full scan. Quick Scan is not able to find all the viruses, because it scans only the most popular registry entries and folders.
You can observe the detected malicious items sorted by their possible harm till the scan process. But to perform any actions against malware, you need to hold on until the scan is over, or to stop the scan.
To set the action for each detected virus or unwanted program, click the arrow in front of the name of the detected virus. By default, all the viruses will be removed to quarantine.
How to remove Woreflint Trojan?
Name: Woreflint
Description: Trojan Woreflint is a kind of virus that infiltrates into your computer, and after that performs different destructive functions. These features depend upon a type of Woreflint trojan: it can act as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the Woreflint trojan. During the last two years, trojans are also dispersed via e-mail attachments, and most of situations utilized for phishing or ransomware infiltration.
Operating System: Windows
Application Category: Trojan