Trojan

Trojan:Win32/Wacatac.A!rfn information

Malware Removal

The Trojan:Win32/Wacatac.A!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Wacatac.A!rfn virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Wacatac.A!rfn?


File Info:

crc32: E2EEEF31
md5: ad359f8ad4776fe8850f99f6282e3ca5
name: 1581237541457.exe
sha1: 6633113b6e0239b3096f671879884df1cc6c3b58
sha256: 2f0f31d6ae2bf56390442db6e3b941d23f16e7fd14e8c6e96f50a85895a9a830
sha512: 1f9c1e93f26faa4d8bf0be6886c8e412421ba9d5d38c6bae9a9b39c8903c6a34e72e20d8f5f3a3d62bd18d35bcfc38ab3c8b7d3137ce66c22bbd4121afac1fb3
ssdeep: 6144:Zbm+A8sF0jzCRRXgF9WaOgSANtMm28YfdI5vQeFr9szc3w5IGUTRlmDfuvqXmX8:Zy4s6j6lgF9WTgdvMX8cdobx3RHR8DW
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: x5982x6709x4fb5x6743x8bf7x8054x7cfbx4f5cx8005
FileVersion: 1.5.0.0
CompanyName: x661fx671fx516d
Comments: x56fdx5bb6x5404x7c7bx89c4x8303x4e0bx8f7d
ProductName: x56fdx5bb6x5404x7c7bx89c4x8303x4e0bx8f7d
ProductVersion: 1.5.0.0
FileDescription: x53efx4ee5x56fdx5bb6x5404x7c7bx89c4x8303x4e0bx8f7d
Translation: 0x0804 0x04b0

Trojan:Win32/Wacatac.A!rfn also known as:

MicroWorld-eScanTrojan.Generic.22023685
FireEyeGeneric.mg.ad359f8ad4776fe8
ALYacTrojan.Generic.22023685
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.Generic.22023685
CrowdStrikewin/malicious_confidence_80% (W)
TrendMicroTROJ_GEN.R035C0PLO19
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.Generic.22023685
AlibabaTrojan:Application/WsGame.fbba94b4
NANO-AntivirusTrojan.Win32.Wsgame.erbvoy
AegisLabTrojan.Win32.Agent.li0G
TencentWin32.Trojan.Psw.Lnnx
Ad-AwareTrojan.Generic.22023685
SophosGeneric PUA GG (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
F-SecureTrojan.TR/PSW.WsGame.eltil
DrWebTrojan.PWS.Wsgame.51637
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Malware.fc
Trapminemalicious.high.ml.score
CMCVirus.Win32.Sality!O
EmsisoftTrojan.Generic.22023685 (B)
WebrootW32.Trojan.Gen
AviraTR/PSW.WsGame.eltil
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1500E05
MicrosoftTrojan:Win32/Wacatac.A!rfn
AhnLab-V3Trojan/Win32.Generic.C2614346
Acronissuspicious
McAfeeRDN/Generic.rp
MAXmalware (ai score=96)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R035C0PLO19
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZexaF.34090.xmuaa02WRyob
AVGWin32:Malware-gen
Cybereasonmalicious.ad4776
Paloaltogeneric.ml

How to remove Trojan:Win32/Wacatac.A!rfn?

Trojan:Win32/Wacatac.A!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment