Malware

Mal/Vawtrak-S removal

Malware Removal

The Mal/Vawtrak-S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Vawtrak-S virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Mimics icon used for popular non-executable file format
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/Vawtrak-S?


File Info:

name: BA0BC712E56B69C8F354.mlw
path: /opt/CAPEv2/storage/binaries/12203c47d4574f99ec950bc4ec920caaa256e4b1154409210a83ef800b8e1738
crc32: 6D6EA383
md5: ba0bc712e56b69c8f35469a40d03eace
sha1: 370db0f18a06e5e16089064bd4efee4de0feeba7
sha256: 12203c47d4574f99ec950bc4ec920caaa256e4b1154409210a83ef800b8e1738
sha512: 2bd4c7caac97b41918c92159213768ec6189cadf64f2e9d92fdc0d1f0c00678998af525b2a9431bc7da379c628586347a3dcec2970db2b14670c8dfdfe68062b
ssdeep: 1536:dg2BobiS4jHHNOeFDAoFJNEiGGRH8Oh98q:Kqo+ftlFDAoFPwGRcOh9d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6D39D323DD0C2B7F6B349B159E14E8EE77BF91A1216194F86D009472C3BAA35C3661B
sha3_384: e03202127d060b2ac8255d9010fc2b2ab562c2680a3decbf3a80dd01552f551f00e740c19fa09ac92021d2d12fe0b480
ep_bytes: 558bec6aff68f8b5400068ac37400064
timestamp: 2015-07-22 08:27:16

Version Info:

BuildVersion: 7, 15, 22, 129
Translation: 0x0419 0x04b0

Mal/Vawtrak-S also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JRZZ
CAT-QuickHealTrojanDownloader.Upatre.RF4
SkyhighBehavesLike.Win32.Downloader.cz
McAfeeDownloader-FAWW!BA0BC712E56B
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPRETrojan.Downloader.JRZZ
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005a9af81 )
BitDefenderTrojan.Downloader.JRZZ
K7GWTrojan ( 004c92211 )
Cybereasonmalicious.18a06e
BitDefenderThetaGen:NN.ZexaF.36792.iqX@aO07wNac
SymantecDownloader.Upatre
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.DQYD
APEXMalicious
ClamAVWin.Downloader.Upatre-7374321-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Dwn.duhhfu
ViRobotTrojan.Win32.Upatre.135168.A
RisingMalware.FakePDF/ICON!1.A24A (CLASSIC)
SophosMal/Vawtrak-S
BaiduWin32.Trojan.Kryptik.ks
F-SecureTrojan.TR/Kryptik.abbogp
DrWebTrojan.DownLoader15.6021
ZillyaDownloader.Upatre.Win32.46892
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ba0bc712e56b69c8
EmsisoftTrojan.Downloader.JRZZ (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan/Generic.bhigq
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Kryptik.abbogp
VaristW32/Trojan.JNBU-7452
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Upatre
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.DLF@5t0aja
ArcabitTrojan.Downloader.JRZZ
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Downloader.JRZZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R159433
Acronissuspicious
VBA32BScope.Malware-Cryptor.Dyllu
ALYacTrojan.Downloader.JRZZ
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.GenAsa!8D+PFuOKM1c
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.DRBQ!tr
AVGWin32:Crypt-SDI [Trj]
AvastWin32:Crypt-SDI [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mal/Vawtrak-S?

Mal/Vawtrak-S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment