Trojan

Trojan.Waski.S28288290 (file analysis)

Malware Removal

The Trojan.Waski.S28288290 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Waski.S28288290 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Waski.S28288290?


File Info:

name: D2A2BAAAB409A729C2EF.mlw
path: /opt/CAPEv2/storage/binaries/8193055d2ea5472a6ef21bd2dc1bdf1cc70f7bf8fba7e60eba61c49b7c3ba2b7
crc32: DAD53FAD
md5: d2a2baaab409a729c2ef6c4952e4e5c6
sha1: e5ec8470118b7ca5145a85aaafe93e50b7123de5
sha256: 8193055d2ea5472a6ef21bd2dc1bdf1cc70f7bf8fba7e60eba61c49b7c3ba2b7
sha512: 03d9c98aa1eb3db2939977866e5f75d70b594419a8159eccac17df415038528014e8809a0f5274e72776f3afc89ddb57ff37842d5f5f61a89501a317551a2ea7
ssdeep: 96:mB7YtevLGa7NBMnwAnQWRRUF2CqDE93Iq2e2yME3dTMlRsfUKqEY9vZxbOb+tGq1:mB7Yt0+QWRRMfykMZlRpZ9vKq1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F412CB799FD45572E3BB8E7589F244C2AA7470233E069C5E50EA03850C23F66ECB1B1E
sha3_384: 49201e43e45f765b1eb7a438ad06b192d32ac3809ed1d452664d7aabec9c27179754c792a2094c1e44dddeb13ec1ecbd
ep_bytes: 81ec3408000053555633f65756897424
timestamp: 2014-05-08 10:44:27

Version Info:

0: [No Data]

Trojan.Waski.S28288290 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JQQT
ClamAVWin.Downloader.Upatre-7392215-0
CAT-QuickHealTrojan.Waski.S28288290
ALYacTrojan.Downloader.JQQT
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Downloader.JQQT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.0118b7
VirITTrojan.Win32.Upatre.AZ
CyrenW32/S-654ac031!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Downloader.JQQT
NANO-AntivirusTrojan.Win32.DownLoad3.czagcy
AvastWin32:Evo-gen [Trj]
TencentTrojan-Downloader.Win32.Upatre.we
EmsisoftTrojan.Downloader.JQQT (B)
F-SecureHeuristic.HEUR/AGEN.1320027
DrWebTrojan.DownLoad3.33216
ZillyaTrojan.Generic.Win32.699290
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.d2a2baaab409a729
SophosMal/EncPk-ACO
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11LLRO4
JiangminTrojanSpy.Zbot.ffhh
WebrootW32.Trojan.Dropper
AviraHEUR/AGEN.1320027
MAXmalware (ai score=85)
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.996
XcitiumTrojWare.Win32.TrojanDownloader.Waski.ADW@8mzp93
ArcabitTrojan.Downloader.JQQT
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojanDownloader:Win32/Upatre.AA
GoogleDetected
AhnLab-V3Trojan/Win32.Upatre.R158192
Acronissuspicious
McAfeeDownloader-FBVU!D2A2BAAAB409
TACHYONTrojan/W32.Tremp.9518
VBA32SScope.Trojan-Downloader.1454
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDropper.Injector!8.DC (TFE:3:JrFJf4jCRlD)
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.B!tr.dldr
BitDefenderThetaGen:NN.ZexaF.36738.auX@am9um2di
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Waski.S28288290?

Trojan.Waski.S28288290 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment