Trojan

How to remove “Trojan.Waski.S28288290”?

Malware Removal

The Trojan.Waski.S28288290 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Waski.S28288290 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Waski.S28288290?


File Info:

name: 8870E40C45108DAACA84.mlw
path: /opt/CAPEv2/storage/binaries/1f480d59cf10c114341f22ef5333bd4fc7103faaffeb655f303712455b0e112e
crc32: 10768CDE
md5: 8870e40c45108daaca841b7fb060ff49
sha1: 1aae890d2265ce8790520e2d227ead120adb565d
sha256: 1f480d59cf10c114341f22ef5333bd4fc7103faaffeb655f303712455b0e112e
sha512: a8b1726e157eb031b1d7bc02c4429018704acb12ab85fc3a7559a90d0eadaab4ffa4c31db1e4f75e5b1ba06eedbaed67cc5fcedda6b198aad9d6d685f5e6d5c6
ssdeep: 384:HxdsQWRIcSBZ18fc2PjgIxCO54eqBRMeN8qlP:nshRSBwc2sIxNWeaRMK8kP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9720F3CAED556B6E37BCAB6CAF645C6FD25B02339029C0E40DB03850C53F96AD9161E
sha3_384: d01f028c82b0ade773330edbd34ffc572fa2b1feb4f3640afbcbc6e6ece88781801b3584e7022aaad1959bccfa92ee73
ep_bytes: 558bec81ec3808000053565733db53ff
timestamp: 2013-12-02 15:44:08

Version Info:

0: [No Data]

Trojan.Waski.S28288290 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.8870e40c45108daa
CAT-QuickHealTrojan.Waski.S28288290
SkyhighBehavesLike.Win32.Generic.lz
McAfeeDownloader-FML!8870E40C4510
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Ppatre.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0059acf21 )
K7GWTrojan-Downloader ( 0048f6391 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Upatre.BV
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Zbot.vho
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad.cqofta
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Waski-A [Trj]
RisingSpyware.Zbot!8.16B (TFE:5:3640qBUlECU)
TACHYONTrojan-Spy/W32.ZBot.16592.E
SophosMal/EncPk-ACO
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.28161
ZillyaDownloader.SmallGen.Win32.2
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Ppatre.Gen.1 (B)
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan.PSE.198EKR5
JiangminTrojanDownloader.Upatre.aerk
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.TrojanDownloader.Waski.AQ@7t0jau
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan-Spy.Win32.Zbot.vho
MicrosoftTrojan:Win32/Waski.A!MTB
VaristW32/S-654ac031!Eldorado
AhnLab-V3Trojan/Win32.Upatre.R282018
Acronissuspicious
BitDefenderThetaAI:Packer.1586FFA720
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=87)
VBA32Trojan.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
TencentTrojan-Spy.Win32.Zbot.hk
YandexTrojan.GenAsa!Iaz+na8i5c0
SentinelOneStatic AI – Malicious PE
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.d2265c
DeepInstinctMALICIOUS

How to remove Trojan.Waski.S28288290?

Trojan.Waski.S28288290 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment