Trojan

Trojan.Wacapew (file analysis)

Malware Removal

The Trojan.Wacapew is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Wacapew virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

downloader.downerapi.com
www.pc6.com
source.downerapi.com
img.downerapi.com

How to determine Trojan.Wacapew?


File Info:

crc32: 0F7710D0
md5: 6defe3d2298fe9e3d802634fd5b2ca38
name: makerom-x86_64.exe_038221655.exe
sha1: 807e2cef24297148286b5c121456bf79dfd5d3b7
sha256: 8b34468070c6a2d9b6977b2999655c64d6dc08143608d8ec34ebd27fedf3c4b2
sha512: 4c3bf016bd3181a796842bb4a170d07c67291004901b119019a6ed26867970b81b51019c5df473479a6da192ff633a6e9a306a7e19a6c247340a2c9a42f6ffd7
ssdeep: 24576:B72j9h9thNLFJPuq5B+t/AJY30XZMl1xDVENTudvXv+cXd:B7ChhPuQtJLJS1x5uTud/v+cXd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Trojan.Wacapew also known as:

MicroWorld-eScanGen:Variant.Adware.Downloader.211
CAT-QuickHealTrojan.Wacapew
McAfeeArtemis!6DEFE3D2298F
CylanceUnsafe
K7AntiVirusRiskware ( 0054404d1 )
BitDefenderGen:Variant.Adware.Downloader.211
K7GWRiskware ( 0054404d1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Adware.Downloader.211
Kasperskynot-a-virus:HEUR:Downloader.Win32.Agent.vho
AlibabaRiskWare:Win32/Downer.dc5c1ef9
ViRobotAdware.Agent.1133912
Ad-AwareGen:Variant.Adware.Downloader.211
SophosGeneric PUA IA (PUA)
ComodoApplicUnwnt@#2wi4glqlv9pp7
F-SecureHeuristic.HEUR/AGEN.1126112
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
MaxSecureTrojan.Malware.75393012.susgen
FireEyeGeneric.mg.6defe3d2298fe9e3
EmsisoftGen:Variant.Adware.Downloader.211 (B)
IkarusPUA.RiskWare.Downer
CyrenW32/Adware.QTAB-0638
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1126112
Endgamemalicious (high confidence)
ArcabitTrojan.Adware.Downloader.211
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Agent.vho
MicrosoftProgram:Win32/Occamy.AA
AhnLab-V3PUP/Win32.Generic.C3478818
VBA32Downloader.Agent
MAXmalware (ai score=62)
MalwarebytesPUP.Optional.FastDownloader
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/RiskWare.Downer.B
TrendMicro-HouseCallTROJ_GEN.R002H0CEP20
RisingAdware.Downloader!1.C41F (CLOUD)
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Agent

How to remove Trojan.Wacapew?

Trojan.Wacapew removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment