Backdoor

Should I remove “Backdoor:Win32/Wavipeg.A”?

Malware Removal

The Backdoor:Win32/Wavipeg.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Wavipeg.A virus can do?

  • Reads data out of its own binary image
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Backdoor:Win32/Wavipeg.A?


File Info:

crc32: 5C8F63C4
md5: 426276ad7569f6c5be81efacc5115dc8
name: 426276AD7569F6C5BE81EFACC5115DC8.mlw
sha1: 760fea3af386a61be5d08296102fd1e0f5bb47b5
sha256: a1f3fb01c487b0112e54d080595b91e34a2f65bcb9630b64610ed4152633498a
sha512: 5b33cd8f119bf79ac1008557854e6338b6f7a05d0311b4edbfc601e5eb410eae67f15278d4ea7b8b7e7b96b04cc814e867633464391447a7805f1b17bb0efdd0
ssdeep: 24576:hb3frTqaFfUodpJ416PRntaprEyblePXTLfTCwCuV9Z:hrTNUUJ4oP/AV4PDLfTXV9Z
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Wavipeg.A also known as:

BkavW32.HfsAutoB.
K7AntiVirusTrojan ( 000449171 )
LionicTrojan.Win32.Foreign.toS6
MicroWorld-eScanGen:Variant.Ulise.5969
CMCTrojan-Ransom.Win32.Foreign!O
CAT-QuickHealTrojan.ForeignPMF.S1796676
ALYacGen:Variant.Ulise.5969
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.3593
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Foreign.fb1a4be5
K7GWTrojan ( 000449171 )
Cybereasonmalicious.d7569f
CyrenW32/A-4a990807!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Agent.NMA
APEXMalicious
AvastWin32:Agent-ARFR [Trj]
ClamAVWin.Trojan.Agent-1187802
GDataGen:Variant.Ulise.5969
KasperskyTrojan-Ransom.Win32.Foreign.njky
BitDefenderGen:Variant.Ulise.5969
NANO-AntivirusTrojan.Win32.RiskGen.cthmhf
TencentWin32.Trojan.Foreign.Pavi
Ad-AwareGen:Variant.Ulise.5969
SophosMal/Agent-ATP
ComodoTrojWare.Win32.Wavipeg.A@6txxfk
F-SecureWorm.WORM/Agent.uwthp
DrWebTrojan.AVKill.28906
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ransomware.th
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.426276ad7569f6c5
EmsisoftGen:Variant.Ulise.5969 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/A-4a990807!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Gen.Bt
AviraWORM/Agent.uwthp
Antiy-AVLTrojan[Ransom]/Win32.Foreign
MicrosoftBackdoor:Win32/Wavipeg.A
JiangminTrojan/Foreign.clf
ArcabitTrojan.Ulise.D1751
ZoneAlarmTrojan-Ransom.Win32.Foreign.njky
AhnLab-V3Trojan/Win32.Ransom.R58523
Acronissuspicious
McAfeeArtemis!426276AD7569
MAXmalware (ai score=83)
VBA32Hoax.Foreign
MalwarebytesTrojan.Agent.FT
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.89 (RDMK:1rO4m3t3VOotDysjorE7yg)
YandexTrojan.Foreign!D3CKrulHjqg
IkarusTrojan.Agent4
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Foreign.ABEW!tr
AVGWin32:Agent-ARFR [Trj]
Qihoo-360Win32/Trojan.78e

How to remove Backdoor:Win32/Wavipeg.A?

Backdoor:Win32/Wavipeg.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment