Trojan

How to remove “TrojanDownloader:Win32/Waski.GEM!MTB”?

Malware Removal

The TrojanDownloader:Win32/Waski.GEM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Waski.GEM!MTB virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Waski.GEM!MTB?


File Info:

name: B7DEEAA66BF914EBE23B.mlw
path: /opt/CAPEv2/storage/binaries/73be96b4d82b950bc95633e92622218a232be698c9d63916a582065b7e540ae9
crc32: 985873C9
md5: b7deeaa66bf914ebe23b51f049c39991
sha1: fea5f0ff0456666695bd164da21b8799c2798941
sha256: 73be96b4d82b950bc95633e92622218a232be698c9d63916a582065b7e540ae9
sha512: e8644b8d009bcebcd1b906ab503bbec3044f290a20c9317d59c3d111d75b8cbe0be52aa26e13ffb75eca6cb6464b0d3c53c59462a4b35c4f293ce50ecd3b1b37
ssdeep: 192:ax1qR5c5Xupmg273DRS49hOlBPYt/JQWRRssHgwlDL0/X:ax4eXupD273DRSAhuB+JQWRRssHgnP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103A25451E2C348D8D2690AF50DDB71B1B6B5105BE221DC991FE9B9B212C31D209FF72E
sha3_384: f6b7e6e26c107fcc25dccccec9a9bd86132897415d28a3fb3dcfe912c25f28015b6f436a38fb9d7f55af48b62ea579b2
ep_bytes: 6a00e8430b0000a300314000e8330b00
timestamp: 2014-05-14 14:26:35

Version Info:

0: [No Data]

TrojanDownloader:Win32/Waski.GEM!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Ipatre.1
FireEyeGeneric.mg.b7deeaa66bf914eb
CAT-QuickHealTrojan.Generic
McAfeeGenericRXAA-AA!B7DEEAA66BF9
CylanceUnsafe
SangforSuspicious.Win32.Save.a
BitDefenderGen:Trojan.Ipatre.1
Cybereasonmalicious.66bf91
BitDefenderThetaGen:NN.ZexaF.34712.auW@aKBigWei
CyrenW32/S-47db96bb!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.E
BaiduWin32.Trojan-Downloader.Waski.a
TrendMicro-HouseCallTROJ_GEN.R002C0DEQ22
ClamAVWin.Dropper.Upatre-9950882-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Zbot.cykone
RisingTrojan.DL.Win32.Upatre.aaa (CLASSIC)
Ad-AwareGen:Trojan.Ipatre.1
SophosMal/Generic-R
ComodoTrojWare.Win32.Spy.Zbot.SOZI@5b5cr1
DrWebTrojan.DownLoad3.33216
TrendMicroTROJ_GEN.R002C0DEQ22
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Ipatre.1 (B)
APEXMalicious
AviraTR/Dropper.Gen
MicrosoftTrojanDownloader:Win32/Waski.GEM!MTB
ArcabitTrojan.Ipatre.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Ipatre.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R106882
ALYacGen:Trojan.Ipatre.1
MAXmalware (ai score=84)
VBA32SScope.Trojan-Downloader.1454
MalwarebytesTrojan.Email.FakeDoc
TencentMalware.Win32.Gencirc.11f6a068
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Waski.E!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Waski.GEM!MTB?

TrojanDownloader:Win32/Waski.GEM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment