Backdoor

Backdoor:Win32/Vawtrak.E malicious file

Malware Removal

The Backdoor:Win32/Vawtrak.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Vawtrak.E virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Creates a copy of itself

How to determine Backdoor:Win32/Vawtrak.E?


File Info:

crc32: C3784D7F
md5: 330e1ca4dfbdac16fd31c0667cee0d1a
name: inst1.exe
sha1: 0cee4080eafad60c336fe2879791d625e92e4615
sha256: 81d1f5a7cac68c88d0a6fc7b909703e893e26d275085031b152c44794f0e0798
sha512: 17fc395ba102a41c7b5fcf87586b2c7725d28333006ebd52296e2b00b4f4f0746da55265beb62316706ef7cd2d291f3c14d5e75c8d76f9d6f7508097e15b2546
ssdeep: 3072:xzefpc+EINrjecUdN/I5SXNfcsYx230Vg5VPY+HU/KFVX+tDuDiB8e96gffPGfr4:1ecN/bCTwXTFZiBR9Rf3GfbaupPcL7v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2013. All rights reserved. Northglide
InternalName: IdletimeoutAsked
FileVersion: 8.1.2.6
CompanyName: Northglide
LegalTrademarks: Copyright 2013. All rights reserved. Northglide
Comments: Poor Feminism Copeiss
ProductName: IdletimeoutAsked
Languages: English
ProductVersion: 8.1.2.6
FileDescription: Poor Feminism Copeiss
OriginalFilename: IdletimeoutAsked
Translation: 0x0409 0x04b0

Backdoor:Win32/Vawtrak.E also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.3441413
FireEyeGeneric.mg.330e1ca4dfbdac16
McAfeeGeneric.cy
ALYacTrojan.GenericKD.3441413
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.3441413
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4dfbda
Invinceaheuristic
SymantecTrojan.Snifula.F
APEXMalicious
GDataTrojan.GenericKD.3441413
KasperskyTrojan-Spy.Win32.Zbot.wzsq
AlibabaTrojanSpy:Win32/Kryptik.b6aa1fc0
NANO-AntivirusTrojan.Win32.Papras.efnjnv
AegisLabTrojan.Win32.Generic.4!c
RisingBackdoor.Vawtrak!8.11D (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.3441413 (B)
F-SecureTrojan.TR/Crypt.XPACK.jixc
DrWebTrojan.PWS.Papras.2166
ZillyaTrojan.Kryptik.Win32.1509354
TrendMicroTROJ_HANCITOR.YYSVN
McAfee-GW-EditionGeneric.cy
Trapminemalicious.high.ml.score
SophosTroj/Vawtrak-HF
IkarusTrojan.Crypt.XPACK
CyrenW32/Trojan.BMPU-6857
JiangminTrojanSpy.Zbot.firr
WebrootBackdoor.Vawtrak.E
AviraTR/Crypt.XPACK.jixc
MAXmalware (ai score=97)
ArcabitTrojan.Generic.D348305
ZoneAlarmTrojan-Spy.Win32.Zbot.wzsq
MicrosoftBackdoor:Win32/Vawtrak.E
AhnLab-V3Trojan/Win32.Agent.C1515409
Acronissuspicious
VBA32BScope.TrojanSpy.Zbot
Ad-AwareTrojan.GenericKD.3441413
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.FUWN
TrendMicro-HouseCallTROJ_HANCITOR.YYSVN
TencentWin32.Trojan-spy.Zbot.Lfzy
YandexTrojanSpy.Zbot!hENdc5mfO2Y
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Vawtrak.HF!tr
BitDefenderThetaGen:NN.ZexaF.34090.rq0@au3mXypi
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM10.2.5DB5.Malware.Gen

How to remove Backdoor:Win32/Vawtrak.E?

Backdoor:Win32/Vawtrak.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment