Trojan

TrojanDownloader:Win32/Waledac.AJ removal tips

Malware Removal

The TrojanDownloader:Win32/Waledac.AJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Waledac.AJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (54 unique times)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Waledac.AJ?


File Info:

name: A7FB0C059DB77C0724E1.mlw
path: /opt/CAPEv2/storage/binaries/0afa64ba7b3a4573ded9ea24510cbddba2e83e02abd2636cbb494e659da00efb
crc32: D2AD4F44
md5: a7fb0c059db77c0724e13ea027a5da04
sha1: 04202589a60252d403086b278b9de0cbe44c6f7a
sha256: 0afa64ba7b3a4573ded9ea24510cbddba2e83e02abd2636cbb494e659da00efb
sha512: a5f0d2a6904214ad452208ef70e08b24f9ede35ff6c8ae469d6dd8d569de41af7f6fdbfd94bd6cb61be1d2f5018cf38e7cb7d4b61084c3358fbc29e10bf45442
ssdeep: 384:IOPgcg1QRt1e+JwZOiNbHmpnCC9plvke:v9gui+2Okipr5ke
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19CE2CA92DADC0776D9A2AA7237F23E28C17C350240947C14BE3D68A9F71FBD68611787
sha3_384: 71c23ff861aadfcb1e78931e9d7c7f438b963c9a7396302f3052d4e172b31d301efdd72f70fe5d2604f864faca85cecc
ep_bytes: 90908bc4663d00f6724c68874fbfff59
timestamp: 2010-07-13 12:44:29

Version Info:

0: [No Data]

TrojanDownloader:Win32/Waledac.AJ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a7fb0c059db77c07
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeeGeneric-FANP!A7FB0C059DB7
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 004ff4611 )
K7AntiVirusTrojan ( 004ff4611 )
BaiduWin32.Trojan.Kryptik.c
CyrenW32/S-60ce1850!Eldorado
SymantecPacked.Generic.461
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BNNW
APEXMalicious
ClamAVWin.Dropper.Kelihos-9754369-0
KasperskyBackdoor.Win32.Hlux.cqg
BitDefenderGen:Variant.FakeAlert.136
MicroWorld-eScanGen:Variant.FakeAlert.136
AvastWin32:Downloader-UWY [Trj]
Ad-AwareGen:Variant.FakeAlert.136
EmsisoftGen:Variant.FakeAlert.136 (B)
ComodoTrojWare.Win32.Kryptik.BLUE@53i51j
DrWebTrojan.DownLoad3.28912
TrendMicroBKDR_KELIHOS.SMF
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
SophosML/PE-A + Troj/FakeAV-GWD
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.FakeAlert.136
JiangminBackdoor/Hlux.fmr
WebrootW32.Yakes.dmyb
AviraTR/Urausy.83916845
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASBOL.BBA
ArcabitTrojan.FakeAlert.136
SUPERAntiSpywareTrojan.Agent/Gen-XPack
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Waledac.AJ
AhnLab-V3Spyware/Win32.Zbot.R86172
BitDefenderThetaGen:NN.ZexaF.34606.cqW@aWsUj5ki
ALYacGen:Variant.FakeAlert.136
VBA32Heur.Trojan.Hlux
MalwarebytesTrojan.MalPack.FFS
TrendMicro-HouseCallBKDR_KELIHOS.SMF
RisingTrojan.Antier!1.9D9B (CLOUD)
YandexTrojan.GenAsa!cHx2EBPkBQI
IkarusBackdoor.Win32.Kelihos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BDPK!tr
AVGWin32:Downloader-UWY [Trj]
Cybereasonmalicious.59db77
PandaTrj/Genetic.gen

How to remove TrojanDownloader:Win32/Waledac.AJ?

TrojanDownloader:Win32/Waledac.AJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment