Backdoor

Backdoor:Win32/Wabot!atmnm removal

Malware Removal

The Backdoor:Win32/Wabot!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Wabot!atmnm virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Wabot!atmnm?


File Info:

name: 39A587A30565401D800D.mlw
path: /opt/CAPEv2/storage/binaries/9be59d4b394c686000d0bf6dfa3dcdd829cc51800b384bf21048fb0531127049
crc32: F61638D1
md5: 39a587a30565401d800de096b7a59e04
sha1: 40a7afa93b76c7ae80ae4cccc935583c676772e2
sha256: 9be59d4b394c686000d0bf6dfa3dcdd829cc51800b384bf21048fb0531127049
sha512: f8c64e67cae1cca43b7e6d7685b4e5460e20c107de504e0dc3de28747a031718bc3cce391e440df1e308cddb1d84587aea42d778a6483c3924ab435aa70c024a
ssdeep: 12288:+71bZJegiUqWe34CfxnWLjvuX6rttYjb2WHeSWo/hMxiJb00Y1sCMfctvCYZSWth:+71bZY2wDkjGKkPN+ilf2q7E0nK15
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B625235FE645BE73C23457B90D0698FCAACB0BE1DDD8915A3F9CCA0F77A52801924B81
sha3_384: c2db71deda16697e03f98a5885f1916cde8e88b0162dc0d04e9b4d2f99d5bb3bdf49383b460d8ac6d7bec9c6b67f2516
ep_bytes: e9926a0000c700010000000f9ac288d6
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Wabot!atmnm also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebTrojan.MulDrop6.64369
MicroWorld-eScanGen:Trojan.ShellIni.@mZ@aGsJv1ei
CAT-QuickHealBackdoor.Wabot.S619505
SkyhighBehavesLike.Win32.Wabot.fc
McAfeeBackDoor-FDOW!39A587A30565
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.305654
BitDefenderThetaAI:Packer.11B697931D
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Delf.NRF
APEXMalicious
TrendMicro-HouseCallBackdoor.Win32.WABOT.SMD
ClamAVWin.Trojan.Wabot-7053120-0
KasperskyHEUR:Trojan.Win32.JTalye.gen
BitDefenderGen:Trojan.ShellIni.@mZ@aGsJv1ei
NANO-AntivirusTrojan.Win32.Delphi.elzgzr
AvastWin32:Delf-VKC [Trj]
TencentTrojan.Win32.Wabot.a
EmsisoftGen:Trojan.ShellIni.@mZ@aGsJv1ei (B)
F-SecureTrojan.TR/Dldr.Delphi.Gen
BaiduWin32.Backdoor.Wabot.a
VIPREGen:Trojan.ShellIni.@mZ@aGsJv1ei
TrendMicroBackdoor.Win32.WABOT.SMD
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.39a587a30565401d
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
JiangminBackdoor/Wabot.z
GoogleDetected
AviraTR/Dldr.Delphi.Gen
VaristW32/Heuristic-114!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.Wabot.a
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Wabot!atmnm
XcitiumBackdoor.Win32.Poison.HYB@3nwaj4
ArcabitTrojan.ShellIni.EFD19A6
ZoneAlarmHEUR:Trojan.Win32.JTalye.gen
GDataWin32.Backdoor.Wabot.A
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.MulDrop
ALYacGen:Trojan.ShellIni.@mZ@aGsJv1ei
Cylanceunsafe
ZonerTrojan.Win32.22025
RisingWorm.Chilly!1.661C (CLASSIC)
YandexTrojan.GenAsa!6ZvkjKYFmdY
IkarusP2P-Worm.Win32.Delf
MaxSecureBackdoor.W32.Wabot.A
FortinetW32/Delf.NRF!tr
AVGWin32:Delf-VKC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudBackdoor:Win/Wabot.B(dyn)

How to remove Backdoor:Win32/Wabot!atmnm?

Backdoor:Win32/Wabot!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment