Remove Win32/Wajagen.a Adware Virus (Feb. 2019 Update)

How irritating is this problem? (19 votes, average: 4.89)

Can’t Remove Win32/Wajagen.a Trojan? This page includes detailed instructions on how to remove Win32/Wajagen.a Trojan that can be found at the bottom half of this article.

Getting your PC infected with Win32/Wajagen.a or any similar virus of the Trojan Horse category can certainly lead to a lot of different problems and issues of all kinds. Therefore, acting quickly and decisively in such a situation is essential and could be the difference between having your virtual security and your PC system compromised and eliminating the threat on time and saving your computer from the Trojan Horse’s attack. Here, our goal is to help our readers obtain a better understanding of the nature of the Trojan Horse infections and the Win32/Wajagen.a virus in particular. We will mainly be focusing on Win32/Wajagen.a as it is one of the newest Trojan Horse representatives and there way too many users who have already fallen victims to it at the time of writing this. We believe that if you know more about this threatening piece of malware and are well aware of its capabilities, its methods of distribution and the courses of action you could take to stop it and remove it, your chances of successfully saving your PC would go up significantly.

The abilities of a Trojan Horse virus

One important characteristic of a lot of Trojans is their ability to carry out different tasks inside the targeted system. Corruption of the system Registry and of important system data, collection and theft of sensitive info about the user and their personal and/or professional life, downloading of Ransomware, Spyware, Rootkits and other nasty threats onto the infected computer and even allowing the hackers behind the attack to remotely control the process on the targeted computer are only some of the most common ways a Trojan virus can be employed. We can’t be sure what Win32/Wajagen.a may try to do on/to your computer but one thing’s certain – you must eliminate the virus before it has had the chance to complete its insidious task.

Win32/Wajagen.a Removal

If you have a Windows virus, continue with the guide below.

If you have a Mac virus, please use our How to remove Ads on Mac guide.

If you have an Android virus, please use our Android Malware Removal guide.

If you have an iPhone virus, please use our iPhone Virus Removal guide


Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).



Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab (the “Details” Tab on Win 8 and 10). Try to determine which processes are dangerous. 


Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at:

Scan Results

Virus Scanner Result

After you open their folder, end the processes that are infected, then delete their folders. 

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections. 


Hold together the Start Key and R. Type appwiz.cpl –> OK.


You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

Type msconfig in the search field and hit enter. A window will pop-up:


Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.


Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

  1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click  Properties.
  2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
  3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.



  • After you complete this step, the threat will be gone from your browsers. Finish the next step as well or it may reappear on a system reboot.

Right click on the browser’s shortcut —> Properties.

NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).


Properties —–> Shortcut. In Target, remove everything after .exe.

ie9-10_512x512  Remove Win32/Wajagen.a from Internet Explorer:

Open IE, click  IE GEAR —–> Manage Add-ons.

pic 3

Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

firefox-512 Remove Win32/Wajagen.a from Firefox:

Open Firefoxclick  mozilla menu  ——-> Add-ons —-> Extensions.

pic 6

Find the adware/malware —> Remove.
chrome-logo-transparent-backgroundRemove Win32/Wajagen.a from Chrome:

Close Chrome. Navigate to:

 C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

Rename the Folder to Backup Default

Rename it to Backup Default. Restart Chrome.


Type Regedit in the windows search field and press Enter.

Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

Some more info about the Trojan category

The versatility and maliciousness of those nasty viruses is only matched by their stealthiness. The hackers behind them tend to use different types of disguise in order to make the users more likely to download the infected on their computers. Here, some of the things that can be employed are fake messages and spam letters, fake update requests and misleading download prompts, pirated downloadables, malicious adverts, etc. In general, anything on the Internet could be turned into a malware carrier if the hacker is skilled enough. This is why you must constantly have your guard up and be on the lookout for suspicious content. Do not trust or interact with anything on the Internet that you are not sure you can trust. Also, getting an antivirus is important in case you don’t have such a program on your PC as it could help you spot Trojans early on. Most infections like Win32/Wajagen.a are known for their overall lack of typical symptoms and though they still might affect your PC performance, cause errors and crashes and in that way get noticed, it’s also possible that there’s nothing visible to suggest that there’s a Trojan on your PC in which case you might not even realize that your computer has been compromised if you don’t have an antivirus tool installed.


Name Win32/Wajagen.a
Type Trojan
Danger Level  High (Trojans are often used as a backdoor for Ransomware)
Symptoms  Pretty much any form unusual PC behavior could be a symptom of a Trojan Horse infection.
Distribution Method Trojans can get distributed via scam pages, pirated program downloads, spam, fake update requests, infected media files, etc.
Detection Tool

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

Leave a Comment