Trojan

Trojan:Win32/Waski!pz malicious file

Malware Removal

The Trojan:Win32/Waski!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Waski!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Waski!pz?


File Info:

name: 3319FBEC054E5B4680BD.mlw
path: /opt/CAPEv2/storage/binaries/8682cf12e0f962acc672e1b79135b5bbed09fcd083443d51ae39d8dd48d4ce41
crc32: 0FED2227
md5: 3319fbec054e5b4680bdf7416d4c3741
sha1: 3d2e0aa554f1da1d977cddd87433a40b8571eedd
sha256: 8682cf12e0f962acc672e1b79135b5bbed09fcd083443d51ae39d8dd48d4ce41
sha512: 2620be0b6f8a8407e3f6c3cd2f77af8fb2c71076045b053d58153b03a423d6e4a5804c93577b7f077ff86eed8449ff858a1884b5626f2e348406bee3a7557a8a
ssdeep: 192:HymTSrQWRIcSvK0OmoarauG+k7v1dlD/W8brAvgigbNPXgt1yUgYxfil7I53arO7:HxTsQWRIcS1forPBnDDKPSXZU73B7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19892233C6EE956B2E3BBCE75C9F651C6B974B42339029C0E40DA03850C53F56EDA1A1E
sha3_384: 2769d760b9b1564b7b509491ed30e4bce81405af17e2a392fe435ed8b53ca5f33c0e7c4ca77ecc5edc315432e29292c2
ep_bytes: 558bec81ec3808000053565733db53ff
timestamp: 2013-12-02 15:44:08

Version Info:

0: [No Data]

Trojan:Win32/Waski!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Malware.Upatre-7004553-0
FireEyeGeneric.mg.3319fbec054e5b46
CAT-QuickHealTrojan.Waski.S28288290
SkyhighBehavesLike.Win32.Generic.lz
McAfeeDownloader-FML!3319FBEC054E
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.SmallGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0059acf21 )
K7GWTrojan-Downloader ( 0048f6391 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Ppatre.Gen.1
VirITTrojan.Win32.Upatre.BV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Zbot.vho
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad.cqofta
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Waski-A [Trj]
TencentTrojan-Spy.Win32.Zbot.hk
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Dldr.Waski.gzsbj
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-ACO
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojanDownloader.Upatre.aerk
GoogleDetected
AviraTR/Dldr.Waski.gzsbj
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.TrojanDownloader.Waski.AQ@7t0jau
MicrosoftTrojan:Win32/Waski!pz
ZoneAlarmHEUR:Trojan-Spy.Win32.Zbot.vho
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/S-654ac031!Eldorado
AhnLab-V3Trojan/Win32.Upatre.R282018
Acronissuspicious
BitDefenderThetaAI:Packer.1586FFA720
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=87)
VBA32Trojan.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingSpyware.Zbot!8.16B (TFE:5:3640qBUlECU)
YandexTrojan.GenAsa!Iaz+na8i5c0
SentinelOneStatic AI – Malicious PE
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.554f1d
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Waski!pz?

Trojan:Win32/Waski!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment