Trojan

Should I remove “Trojan.Downloader.WK”?

Malware Removal

The Trojan.Downloader.WK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.WK virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan.Downloader.WK?


File Info:

name: E470B7538DC075294532.mlw
path: /opt/CAPEv2/storage/binaries/019874898284935719dc74a6699fb822e20cdb8e3a96a7dc8ec4f625e3f1116e
crc32: 0897B6D3
md5: e470b7538dc075294532d8467b1516f8
sha1: 2549bd733c84677a4e145051f07d93434c8a555d
sha256: 019874898284935719dc74a6699fb822e20cdb8e3a96a7dc8ec4f625e3f1116e
sha512: ca448025e195275085566b0fe9c771be1ba2d257c1e6257f899a7b706fdca1f7b1e32154573f2883bf341bba0c3114c4c6411ebfd29ec528eb61929ad00ef371
ssdeep: 192:T6qhdbSbLCNmOWN4K0uof5CQEVH9Ol8H9B41oynAmDI98lR4oSdIZYRyODD7c+KN:esxmOWXDAvE2lw41lDI98MDL7QYq1N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1448209476AD519F2FBA4863006FF07B76776609506B9A6936E20DC0D4C372A39B231CE
sha3_384: 746e7d91428c6b631315f60bca3457cd1fa3e543f61e750dae44a0a0860b536389bb28fb94be7ef3d7759e2f310b6f7d
ep_bytes: 558bec6aff68a835400068442e400064
timestamp: 2017-03-21 18:33:02

Version Info:

CompanyName:
FileDescription: Microsoft MFC Application
FileVersion: 1, 0, 0, 1
InternalName: MMagicIII
LegalCopyright: Copyright (C) 2013
LegalTrademarks:
OriginalFilename: MMagicIII.EXE
ProductName: MMagicIII Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Trojan.Downloader.WK also known as:

BkavW32.Common.5BC1011B
LionicTrojan.Win32.OnLineGames.lulb
DrWebTrojan.DownLoader24.49746
MicroWorld-eScanGen:Variant.Ulise.212095
FireEyeGen:Variant.Ulise.212095
SkyhighGeneric Trojan.fc
McAfeeGeneric Trojan.fc
MalwarebytesTrojan.Downloader.WK
VIPREGen:Variant.Ulise.212095
SangforDownloader.Win32.Demp.V9l9
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDropper:Win32/Trayntadd.3a28d1c4
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.bq0@aSrKLcpi
VirITTrojan.Win32.Dnldr24.CVPI
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.AWT
TrendMicro-HouseCallTROJ_DEMP.G
CynetMalicious (score: 99)
BitDefenderGen:Variant.Ulise.212095
NANO-AntivirusTrojan.Win32.Demp.felhrx
F-SecureTrojan.TR/Dldr.Small.vezid
ZillyaDropper.Demp.Win32.2474
TrendMicroTROJ_DEMP.G
SophosMal/Generic-R
JiangminTrojanDropper.Demp.bnr
AviraTR/Dldr.Small.vezid
MAXmalware (ai score=100)
Antiy-AVLTrojan[APT]/Win32.Tick
XcitiumMalware@#1umnibcn5k1jt
ArcabitTrojan.Ulise.D33C7F
ViRobotDropper.S.Agent.17920.NO
ZoneAlarmTrojan-Dropper.Win32.Demp.aswa
GDataGen:Variant.Ulise.212095
GoogleDetected
AhnLab-V3Trojan/Win32.Homamdown.R230536
VBA32TrojanDropper.Demp
ALYacTrojan.Dropper.17920C
TACHYONTrojan/W32.Dropper.17920
DeepInstinctMALICIOUS
Cylanceunsafe
APEXMalicious
TencentMalware.Win32.Gencirc.10bb9270
YandexTrojan.DownLoader!5DQYB5AuUNI
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Malware.10833744.susgen
FortinetW32/Demp.ASWA!tr
Cybereasonmalicious.38dc07
PandaTrj/CI.A
alibabacloudSuspicious

How to remove Trojan.Downloader.WK?

Trojan.Downloader.WK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment