Trojan

Waski.Trojan.Downloader.DDS removal tips

Malware Removal

The Waski.Trojan.Downloader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Waski.Trojan.Downloader.DDS virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Waski.Trojan.Downloader.DDS?


File Info:

name: A64CC3BC38442209D4C4.mlw
path: /opt/CAPEv2/storage/binaries/006caeadbcbceebd2af1269216f2441dd2b4851850916c73628e278a21527322
crc32: 24175F2F
md5: a64cc3bc38442209d4c4aedc5aef4853
sha1: abb04e45f6319c9df5efc5d8d48f49a8f80cc886
sha256: 006caeadbcbceebd2af1269216f2441dd2b4851850916c73628e278a21527322
sha512: dc11f770f29d4347fbe6f9d2e408cda1c7e8190c484cdef75fe6db1a65054fa638f9581e26ee7a1e30277a26deb7539e0e6cf33b0143982a5116ca1cb35916ca
ssdeep: 192:A0KdpgOE+DwX+i/oheTdNuLLrH4D98Q2JiupC1tS21QCFaI1n2Xiy+:9kGAu+WUO24D944SCFb1nQ+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9926025B5C40765E2B3BA7278EFD69566107CAF3718560E2FC23F4208C2B1279DE68C
sha3_384: 301a8d44791c7b7f1461dae3cfcdd05104258d0d4ec70bbe970e1843168afa774d210d837e2d872b8a6b073bad138d6a
ep_bytes: 558bec83c4dcff15002040006a00ff15
timestamp: 2013-07-12 09:21:19

Version Info:

0: [No Data]

Waski.Trojan.Downloader.DDS also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1632044
ClamAVWin.Trojan.Bublik-414
CAT-QuickHealTrojanDownloader.Upatre.A4
McAfeeDownloader-FSH
CylanceUnsafe
ZillyaTrojan.Bublik.Win32.13450
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0040f7f11 )
K7GWTrojan-Downloader ( 0040f7f11 )
Cybereasonmalicious.c38442
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Crypt3.HDN
CyrenW32/Trojan.FQCN-4930
SymantecDownloader.Upatre!gen5
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.A
ZonerTrojan.Win32.22256
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Bublik.cics
BitDefenderTrojan.GenericKD.1632044
NANO-AntivirusTrojan.Win32.DownLoad3.cwdqvh
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Agent-AUID [Trj]
TencentTrojan-Downloader.Win32.Waski.16000151
Ad-AwareTrojan.GenericKD.1632044
EmsisoftTrojan.GenericKD.1632044 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.ZR@59gqq9
DrWebTrojan.DownLoad3.28161
VIPRETrojan.GenericKD.1632044
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.lm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a64cc3bc38442209
SophosML/PE-A + Troj/Agent-AGQB
IkarusTrojan.Zbot
GDataTrojan.GenericKD.1632044
JiangminTrojan/Bublik.kun
AviraTR/AD.Yarwi.Y.815
Antiy-AVLTrojan/Win32.Bublik
ArcabitTrojan.Generic.D18E72C
MicrosoftTrojan:Win32/Trickbot.GML!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R103717
Acronissuspicious
VBA32Trojan.Bublik
ALYacTrojan.GenericKD.1632044
MAXmalware (ai score=82)
MalwarebytesWaski.Trojan.Downloader.DDS
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.DL.Win32.Upatre.afc (CLASSIC)
YandexTrojan.Bublik!yAJ8E3NlTDM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.GQIX!tr
BitDefenderThetaGen:NN.ZexaF.34784.bq1@aWy@Udfi
AVGWin32:Agent-AUID [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Waski.Trojan.Downloader.DDS?

Waski.Trojan.Downloader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment