Trojan

Win32/TrojanDownloader.Wauchos.AE (file analysis)

Malware Removal

The Win32/TrojanDownloader.Wauchos.AE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Wauchos.AE virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/TrojanDownloader.Wauchos.AE?


File Info:

crc32: 1BA5C55C
md5: d65faefda9c995bbf2e3ea2b20fe8ee5
name: D65FAEFDA9C995BBF2E3EA2B20FE8EE5.mlw
sha1: de8c051d8817493e69e775918010e83454397927
sha256: dd842204914cce067cf72295ef2303fa39e464e381fbae9b657103b90c5ecfec
sha512: a40e75b6da2c77d69f8ccb77de6a087bf79a7214c0f1c19aff24c2e79d6429897ff5b18880f77360734ea6a28d4dd5cb82f0507b9e2b8dd2023980b11a1155a3
ssdeep: 1536:orMbuD3l1aX7hmzUhK5NS3pasH4gWZki0orr8nvwFdk4DpC9wlYSyvh1FQypMvGL:GMCD112hmsRYsHxWZk4r8vwFdkX8xyvf
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

ProductName: aJgcuuNwXpuJ
FileVersion: 19.1.13.9
CompanyName: HnhzMVhBJYFx
Translation: 0x0000 0x04e4

Win32/TrojanDownloader.Wauchos.AE also known as:

DrWebBackDoor.Blackshades.32
MicroWorld-eScanTrojan.GenericKD.32812209
FireEyeGeneric.mg.d65faefda9c995bb
ALYacTrojan.GenericKD.32812209
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusRiskware ( 0040f0f51 )
BitDefenderTrojan.GenericKD.32812209
K7GWRiskware ( 0040f0f51 )
Cybereasonmalicious.da9c99
BitDefenderThetaGen:NN.ZedlaF.34804.fO4@aCqqu4c
CyrenW32/Trojan.AQPX-2970
SymantecTrojan.Gen.MBT
TotalDefenseWin32/Gamarue.cKRLaN
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Blocker.chlkbt
TACHYONTrojan/W32.Blocker.87748
SophosTroj/Inject-APD
F-SecureHeuristic.HEUR/AGEN.1132688
McAfee-GW-EditionBehavesLike.Win32.Dropper.mc
EmsisoftTrojan.GenericKD.32812209 (B)
GDataTrojan.GenericKD.32812209
AviraHEUR/AGEN.1132688
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D1F4ACB1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Gamarue
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Tepfer.C201589
McAfeeArtemis!D65FAEFDA9C9
MAXmalware (ai score=88)
PandaTrj/CI.A
ESET-NOD32Win32/TrojanDownloader.Wauchos.AE
TencentWin32.Trojan.Generic.Wqmx
YandexTrojan.GenAsa!kJf1iTWSWdk
FortinetW32/Injector.ANHO
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/Malware.QVM20.Gen

How to remove Win32/TrojanDownloader.Wauchos.AE?

Win32/TrojanDownloader.Wauchos.AE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment