Malware

WAT:Blacked-I removal guide

Malware Removal

The WAT:Blacked-I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WAT:Blacked-I virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Andromeda/Gamarue malware
  • Detects Sandboxie through the presence of a library
  • Attempts to stop active services
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Anomalous binary characteristics
  • Attempts to modify user notification settings

Related domains:

resa.in

How to determine WAT:Blacked-I?


File Info:

crc32: AE4BE538
md5: 5ed632bd1c4741d0ab145c446d5570b4
name: 5ED632BD1C4741D0AB145C446D5570B4.mlw
sha1: 8b4c945bbcab8981df54e1d8456b77e88ea92926
sha256: 221505d34a14cfc8a1d25dc4c05f21be409c9002da92e554de334ef0bc1bb3b3
sha512: 7af4fba19002db7f91ef352325f2c3e70a8ca63b601fab7323f76d788ff1b59142281e564a193995a42a1cef1a0de2437d878c27efb3dfe42b6adecdfceb430c
ssdeep: 6144:HjMIl9Yz2aTLRWpAe/h1rSPYFVqQ1oWehid8YMNtkSvF4dcT:HOTLc+YXrOOxMvN4WT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Married Eddy stomach stronger
InternalName: Outline.exe
FileVersion: 2.47.77.0
CompanyName: Tower arrow mistake
LegalTrademarks: Fewer author magnet locate worry unknown owner
Comments: Stared atomic
ProductName: Burn
ProductVersion: 2.47.77.0
FileDescription: April influence anyway
OriginalFilename: Outline.exe
Translation: 0x081a 0x081a

WAT:Blacked-I also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner2.1926
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.454801
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.d1c474
CyrenW32/A-aceeedc0!Eldorado
ESET-NOD32a variant of Win32/Injector.BJQP
APEXMalicious
AvastWAT:Blacked-I
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.454801
MicroWorld-eScanGen:Variant.Ursu.454801
Ad-AwareGen:Variant.Ursu.454801
SophosML/PE-A
ComodoTrojWare.Win32.Yakes.DNG@5fm8p5
BitDefenderThetaGen:NN.ZexaF.34294.vy0aaqI!FqpO
FireEyeGeneric.mg.5ed632bd1c4741d0
EmsisoftGen:Variant.Ursu.454801 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1106429
Antiy-AVLTrojan/Generic.ASMalwS.B7B037
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Yakes
GDataGen:Variant.Ursu.454801
AhnLab-V3Dropper/Win32.Necurs.R118809
McAfeeArtemis!5ED632BD1C47
MAXmalware (ai score=83)
VBA32Malware-Cryptor.Limpopo
MalwarebytesRansom.Agent.ED
YandexTrojan.GenAsa!PXYRykNug7g
MaxSecureTrojan.Malware.300983.susgen
AVGWAT:Blacked-I

How to remove WAT:Blacked-I?

WAT:Blacked-I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment