Trojan

How to remove “TrojanDropper:Win32/Wacatac.B!ml”?

Malware Removal

The TrojanDropper:Win32/Wacatac.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Wacatac.B!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk

How to determine TrojanDropper:Win32/Wacatac.B!ml?


File Info:

name: 9184EDC65952A5A1CBC1.mlw
path: /opt/CAPEv2/storage/binaries/7787a448af8ca26bea17057ac76f6e2847496f7ea3b6ca6b4b28f02f15d5a8bf
crc32: 796883A3
md5: 9184edc65952a5a1cbc1940790cc116d
sha1: cd4576ed35aaa57509c40ed63c77c722def260d1
sha256: 7787a448af8ca26bea17057ac76f6e2847496f7ea3b6ca6b4b28f02f15d5a8bf
sha512: 8830e0758106172649893dc77baa3ebb835fd4d9ae212c1992a9db4333f6b3b366c22e7cc626f6f40f9e5249a320b16889125c1e5e5bea1db91af0fa2f644890
ssdeep: 12288:uaHc64b888888888888W88888888888cxscV7TdjL47zdU5imF4pyhk33rD+zG/d:F861iW7uvmQGg6qezG/aYFkJR30F6rpQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11CF40253B3C30071F4615A349C7680049D6779BD0AF4A0A62EFDDB4E4EBA7C68C76B62
sha3_384: 5ccff293161617c28872c02996a0c10981d34592dc02447e8b9e660667c4c5b00bda0ed9dceaf8bd5c91ff646835e329
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2018-06-14 13:27:46

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion: 103.172
LegalCopyright:
ProductName:
ProductVersion: 103.172
Translation: 0x0000 0x04b0

TrojanDropper:Win32/Wacatac.B!ml also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Addrop.A.439007C2
FireEyeGeneric.Addrop.A.439007C2
ALYacGeneric.Addrop.A.439007C2
CylanceUnsafe
Sangfor[INNO_1]
K7AntiVirusTrojan ( 0053aeb31 )
AlibabaTrojanSpy:Win32/Addrop.04c23023
K7GWTrojan ( 0053aeb31 )
Cybereasonmalicious.d35aaa
CyrenW32/Addrop.D.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Addrop.CH
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Agentino-9874843-0
KasperskyUDS:Trojan-Spy.Win32.Noon.gen
BitDefenderGeneric.Addrop.A.439007C2
SUPERAntiSpywareTrojan.Agent/Gen-DropperAddrop
AvastFileRepMalware [Adw]
TencentWin32.Trojan-spy.Noon.Hryi
EmsisoftAdware.Dropper (A)
F-SecureTrojan.TR/Crypt.XPACK.Gen8
DrWebAdware.OxyPumper.18
VIPREGeneric.Addrop.A.439007C2
TrendMicroTROJ_GEN.R002C0PGC22
McAfee-GW-EditionBehavesLike.Win32.FileTour.bc
SophosMal/Generic-S
IkarusTrojan-Dropper.Addrop
GDataGeneric.Addrop.A.439007C2
JiangminTrojanDropper.Agentino.a
AviraTR/Crypt.XPACK.Gen8
ArcabitGeneric.Addrop.A.439007C2
ViRobotTrojan.Win32.Z.Addrop.762945.FO
ZoneAlarmUDS:Trojan-Spy.Win32.Noon.gen
MicrosoftTrojanDropper:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R503075
Acronissuspicious
McAfeeRDN/Generic Dropper
MalwarebytesMalware.AI.2298992223
TrendMicro-HouseCallTROJ_GEN.R002C0PGC22
RisingDownloader.TaskLoader/ARCHIVE!1.CDEA (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Addrop.CH!tr
AVGFileRepMalware [Adw]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove TrojanDropper:Win32/Wacatac.B!ml?

TrojanDropper:Win32/Wacatac.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment