wowst.exe

The executable wowst.exe has been detected as malware by 36 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘wowsos’.
MD5:
cf59b1fab5a8b14c9aa371e1eac3ba26

SHA-1:
5fc517a95a7a6686b956eaf8d6f64cf39dfd961a

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
4/25/2024 3:13:32 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.5022341
927

Agnitum Outpost
Worm.AutoRun
7.1.1

AhnLab V3 Security
Win-Trojan/MalPackedD.suspicious
2014.07.17

Avira AntiVirus
TR/PSW.OnLineGame.G
7.11.162.16

avast!
Win32:OnLineGames-FVA [Cryp]
2014.9-140722

AVG
Worm/Generic2
2015.0.3405

Baidu Antivirus
Trojan.Win32.Klone
4.0.3.14722

Bitdefender
Trojan.Generic.5022341
1.0.20.1015

Bkav FE
W32.KavocosG
1.3.0.4959

Comodo Security
TrojWare.Win32.Trojan.Agent.Gen
18876

Dr.Web
Trojan.PWS.Gamania.27534
9.0.1.0203

Emsisoft Anti-Malware
Trojan.Generic.5022341
8.14.07.22.06

ESET NOD32
Win32/PSW.OnLineGames.QKR
8.10109

F-Prot
W32/OnlineGames.FW.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.5022341
11.2014-22-07_3

G Data
Trojan.Generic.5022341
14.7.24

IKARUS anti.virus
Trojan-GameThief.Win32.Magania
t3scan.1.6.1.0

K7 AntiVirus
Password-Stealer
13.180.12747

Kaspersky
Packed.Win32.Klone
14.0.0.3521

McAfee
RDN/Generic.bfr!a
5600.7061

Microsoft Security Essentials
Worm:Win32/Taterf.gen!E
1.10802

MicroWorld eScan
Trojan.Generic.5022341
15.0.0.609

NANO AntiVirus
Trojan.Win32.Klone.ioing
0.28.2.60881

Norman
Suspicious_Gen2.EQXAD
11.20140722

nProtect
Trojan/W32.Agent.175616.ED
14.07.16.01

Panda Antivirus
Generic Trojan
14.07.22.06

Qihoo 360 Security
Win32/Trojan.PSW.fee
1.0.0.1015

Quick Heal
Trojan.Klone.bq.cw7
7.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.125261A6!307388838
23.00.65.14720

Sophos
Mal/EncPk-ADE
4.98

Trend Micro House Call
Mal_OLGM-41
7.2.203

Trend Micro
Mal_OLGM-41
10.465.22

Vba32 AntiVirus
BScope.Trojan.SvcHorse.01643
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
31338

ViRobot
Trojan.Win32.Klone.175616.A
2011.4.7.4223

Zillya! Antivirus
Worm.AutoRun.Win32.24486
2.0.0.1860

File size:
171.5 KB (175,616 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\wowst.exe

File PE Metadata
Compilation timestamp:
10/19/2010 11:16:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
38.18

CTPH (ssdeep):
3072:dNoltx+LQEGNlmkSbhp8ltdbsTlMrwC15B2hM3QdLDjrAVIssWJwNYxD3WwiROs+:2WQT3mk6hpUwgB2agNbSIssNaD3WROs+

Entry address:
0x8C001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, C0, 08, 00, 83, BD, 22, 04, 00, 00, 00, 89, 9D, 22, 04, 00, 00, 0F, 85, 65, 03, 00, 00, 8D, 85, 2E, 04, 00, 00, 50, FF, 95, 4D, 0F, 00, 00, 89, 85, 26, 04, 00, 00, 8B, F8, 8D, 5D, 5E, 53, 50, FF, 95, 49, 0F, 00, 00, 89, 85, 4D, 05, 00, 00, 8D, 5D, 6B, 53, 57, FF, 95, 49, 0F, 00, 00, 89, 85, 51, 05, 00, 00, 8D, 45, 77, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72...
 
[+]

Entropy:
7.8550

Packer / compiler:
ASPack v2.12

Code size:
276 KB (282,624 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
wowsos

Command:
C:\Windows\System32\wowst.exe


Remove wowst.exe - Powered by Reason Core Security