Trojan

Trojan:Win32/Wacatac.B!rfn removal guide

Malware Removal

The Trojan:Win32/Wacatac.B!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Wacatac.B!rfn virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
rb3.ftnt.io

How to determine Trojan:Win32/Wacatac.B!rfn?


File Info:

crc32: 851E42D9
md5: 813cd1bba40299af74c3a6045d64240e
name: fsa_downloader_8673e7.exe
sha1: f31fea6a7ad5b00df76fb747a8dabfcad27e3fb2
sha256: e39c1bf2d86048202f8c9c0d5e4f077368880f2b913870436e1ec56c588673e7
sha512: e27ae882001232655b2ad01555c9dfdc9b0ba7d755858fa5fdfea586d72135ed1f92b1f1895343c439c395f2db0efd59815f6c4d80e416e0f642ae946b9069fc
ssdeep: 48:odTxwOZv1wOZGZdPkwOW1wAPFsXEJfmbJUr5BPr:oJxwOZv1wOZGZdPkwOW1wAPF+OfmdS5
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Wacatac.B!rfn also known as:

MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.813cd1bba40299af
McAfeeGenericRXHA-OK!813CD1BBA402
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Small!cobra (v)
AegisLabTrojan.Win32.TestSample.4!c
SangforMalware
BitDefenderTrojan.TestSample.B
Cybereasonmalicious.ba4029
F-ProtW32/Downloader-Sml!Eldorado
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataTrojan.TestSample.B
Endgamemalicious (high confidence)
EmsisoftTrojan.TestSample.B (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
Invinceaheuristic
McAfee-GW-EditionGenericRXHA-OK!813CD1BBA402
SophosTroj/AutoG-ER
IkarusTrojan.TestSample
CyrenW32/Downloader-Sml!Eldorado
MaxSecureTrojan.Malware.74274700.susgen
AviraTR/Crypt.XPACK.Gen
WebrootW32.Trojan.Gen
MAXmalware (ai score=94)
ArcabitTrojan.TestSample.B
MicrosoftTrojan:Win32/Wacatac.B!rfn
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
VBA32suspected of Trojan.Downloader.gen.h
ALYacTrojan.TestSample.B
Ad-AwareTrojan.TestSample.B
MalwarebytesTrojan.TestFile
RisingTrojan.Wacatac!8.10C01 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZexaF.34084.amW@a4Uqt!o
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM20.1.DDE7.Malware.Gen

How to remove Trojan:Win32/Wacatac.B!rfn?

Trojan:Win32/Wacatac.B!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment