Backdoor

Backdoor.Win32.Wabot.a removal guide

Malware Removal

The Backdoor.Win32.Wabot.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Wabot.a virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Wabot.a?


File Info:

name: 842E44A2A68E9DF77766.mlw
path: /opt/CAPEv2/storage/binaries/5cbbd284be0c2c7b8834a9bb84691839c17e246cc3d67b3e9961a49a2f2d155a
crc32: D59804E5
md5: 842e44a2a68e9df77766f87f5cdad46d
sha1: 0d09ad714cba5f95993851f90f54c31e5d8e5fe9
sha256: 5cbbd284be0c2c7b8834a9bb84691839c17e246cc3d67b3e9961a49a2f2d155a
sha512: 014ba3ca08952209261f326d41d7f088179df4cff240aee164011b490abf4ed2d37db83eaa9b05f0f5d81bfc105e8d47a027063301e505b3751125aef5ef880d
ssdeep: 1536:BxnhmuHsywOKwrpE4UN4PSPd2QiYrq8q9vlXhmKgRnjK6IU98xq:3A+lp/6Pd/fqHXhq3I6N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156A3020AF55DC693D90CD1344056F0DA59EDAC2731019BABF3C00DFAA9ADB2C6A797A0
sha3_384: dc815d430f3062fd0aaa064522774f188a16f67ab391bbb56d5287d4314e4c0022c6069d76ee2a072d38e40c65a7f786
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Win32.Wabot.a also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.60021847
FireEyeGeneric.mg.842e44a2a68e9df7
McAfeeGenericRXAA-AA!842E44A2A68E
CylanceUnsafe
ZillyaBackdoor.Wabot.Win32.2319
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKD.60021847
K7GWTrojan ( 00129bd51 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Backdoor.Wabot.a
CyrenW32/Wabot.K.gen!Eldorado
SymantecW32.Wabot
ESET-NOD32a variant of Win32/Delf.NRF
APEXMalicious
AvastWin32:Delf-VKB [Trj]
ClamAVWin.Trojan.Wabot-9783917-0
KasperskyBackdoor.Win32.Wabot.a
NANO-AntivirusTrojan.Win32.Delf.eqwfrm
RisingBackdoor.Wabot!8.31C (RDMK:cmRtazqO33mu/KipRfnnMgnlNaOy)
Ad-AwareTrojan.GenericKD.60021847
SophosML/PE-A + Troj/Luiha-M
ComodoBackdoor.Win32.Wabot.A@4knk5y
DrWebTrojan.MulDrop6.64369
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
TrendMicroBackdoor.Win32.WABOT.SMD
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nc
EmsisoftTrojan.GenericKD.60021847 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.60021847
JiangminWorm.Generic.gbw
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.C66A
MicrosoftBackdoor:Win32/Wabot.A
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Wabot.R222262
Acronissuspicious
BitDefenderThetaAI:Packer.FC0CC1B21D
ALYacTrojan.GenericKD.60021847
MAXmalware (ai score=82)
VBA32Backdoor.Wabot
MalwarebytesBackdoor.Wabot
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.Win32.WABOT.SMD
TencentTrojan.Win32.Wabot.a
YandexBackdoor.Wabot!sCKKxb6+WV8
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.NRF!tr
AVGWin32:Delf-VKB [Trj]
Cybereasonmalicious.2a68e9

How to remove Backdoor.Win32.Wabot.a?

Backdoor.Win32.Wabot.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment