Trojan

Trojan.Wdfload removal instruction

Malware Removal

The Trojan.Wdfload is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Wdfload virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan.Wdfload?


File Info:

crc32: 389130A0
md5: f1ea04caa25a44e504c794dc0ac5872e
name: upload_file
sha1: 12d1b47f4d2a29b6ff6dcde5ff4599009544ab61
sha256: 5f45455780932616a1109057e76b4e6ad3444db6371405b96152379ac100767c
sha512: 838257ef90fea3f3b9925ef12c332f9e288d16f1db8022b21156ad2e4bd0514a71b70f3f02f7d9300dac4fefbd73b7bea580754ca4bba2d1973fac64f2b0db40
ssdeep: 49152:EL1FwTMNd9pCFS7T2gqVNslBRDWm860odKNbttVUu+N3ppe1XHEoIguk:EBFwW9p/2gqVClBR6p6fMNbh+N3pA0o
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: Set-up inject.exe
FileVersion: 1.0.0.0
CompanyName: GoogleUpdate
LegalTrademarks: GoogleUpdate
Comments: GoogleUpdate
ProductName: GoogleUpdate
ProductVersion: 1.0.0.0
FileDescription: GoogleUpdate
OriginalFilename: Set-up inject.exe

Trojan.Wdfload also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.700236
FireEyeGeneric.mg.f1ea04caa25a44e5
McAfeeArtemis!F1EA04CAA25A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Bladabindi.m!c
K7AntiVirusTrojan ( 00568c561 )
BitDefenderGen:Variant.Razy.700236
K7GWTrojan ( 00568c561 )
Cybereasonmalicious.f4d2a2
TrendMicroTROJ_GEN.R014C0WGS20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
AlibabaBackdoor:MSIL/Bladabindi.29e0bcba
Ad-AwareGen:Variant.Razy.700236
EmsisoftGen:Variant.Razy.700236 (B)
F-SecureHeuristic.HEUR/AGEN.1136325
Invinceaheuristic
SophosMal/Generic-S
IkarusTrojan-Dropper.MSIL.Agent
CyrenW32/Trojan.EQTK-9386
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1136325
ArcabitTrojan.Razy.DAAF4C
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataMSIL.Backdoor.Bladabindi.EX9FLZ
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZemsilF.34144.ts0@aiZe38m
ALYacGen:Variant.Razy.700236
MAXmalware (ai score=80)
MalwarebytesTrojan.Wdfload
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.EVI
TrendMicro-HouseCallTROJ_GEN.R014C0WGS20
RisingBackdoor.Bladabindi!8.B1F (CLOUD)
SentinelOneDFI – Malicious PE
FortinetMSIL/Agent.EVI!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM03.0.E3FE.Malware.Gen

How to remove Trojan.Wdfload?

Trojan.Wdfload removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment