Home Malware Programs Trojans Trojan.Waldek

Trojan.Waldek

Posted: March 24, 2016

Threat Metric

Ranking: 14,706
Threat Level: 8/10
Infected PCs: 7,272
First Seen: March 24, 2016
Last Seen: January 24, 2025
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\csrssf.exe File name: csrssf.exe
Size: 2.17 MB (2174976 bytes)
MD5: 4458fe6cc8742bcc13b3cf3789e01e2c
Detection count: 438
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: May 14, 2016
%APPDATA%\XkNlZGJZXl8x\gjhax_32.exe File name: gjhax_32.exe
Size: 269.82 KB (269824 bytes)
MD5: 828f0f16fc49f971dca3335b57a8a8eb
Detection count: 169
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\XkNlZGJZXl8x
Group: Malware file
Last Updated: December 17, 2016
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\loader.exe File name: loader.exe
Size: 132.93 KB (132931 bytes)
MD5: a0cca2c4851b76850d42d8fd14e4c96c
Detection count: 126
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\loader.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\autorun.exe File name: autorun.exe
Size: 86.01 KB (86016 bytes)
MD5: c210ee79c2200e153e0f747496ee19a8
Detection count: 115
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\autorun.exe
Group: Malware file
Last Updated: September 26, 2022
file.exe File name: file.exe
Size: 155.74 KB (155743 bytes)
MD5: 217c614a50c471d5a9f0b5fe08ec4fc6
Detection count: 99
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 21, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\Host[NUMBERS].exe%ALLUSERSPROFILE%\Processmanager.exe%ALLUSERSPROFILE%\SearchEngine.exe%ALLUSERSPROFILE%\TimeManager.exe%APPDATA%\autorun.exe%APPDATA%\bild.exe%APPDATA%\build.exe%APPDATA%\sas[RANDOM CHARACTERS].exe%APPDATA%\Soft\olp32.exe
Loading...