Ransom Trojan

How to remove “BScope.TrojanRansom.Wadhrama”?

Malware Removal

The BScope.TrojanRansom.Wadhrama is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanRansom.Wadhrama virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine BScope.TrojanRansom.Wadhrama?


File Info:

crc32: 86B4B1D8
md5: 956cefaa3b8697209c0e63352c8c0386
name: 956CEFAA3B8697209C0E63352C8C0386.mlw
sha1: fb8cee66375de09a565b109dc6a3429996047f3c
sha256: 4e368b0c3a5a9f9ac0d0500c17340d9f51945bbef1892d0e01560521ff260e1a
sha512: b5d700cdc48ccec75edfee7e885caef5862cc983ac185b91a457527f29ec2f9432000187630fd933523bbe187eeb7361f119a385ce1f21a1b787da1449a3c1dd
ssdeep: 6144:te9M/OoHy6qoCUpKv2i1Q8AOe0s2ukfPUGG4ZfKwa7Uzeb:te9HoHyT/Udi1jxUVafywzeb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, dohbujop
FileVersion: 3.7.9
Translation: 0x0809 0x04b0

BScope.TrojanRansom.Wadhrama also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.49533
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
CAT-QuickHealTrojan.Chapak.ZZ5
Qihoo-360Win32/Trojan.Ransom.ec9
McAfeeGenericRXFW-DA!956CEFAA3B86
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.6553
SangforWin.Packed.Gandcrab-6520432-4
K7AntiVirusTrojan ( 00534b9f1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 00534b9f1 )
Cybereasonmalicious.a3b869
BitDefenderThetaGen:NN.ZexaF.34590.ty1@amVWQ4ci
CyrenW32/S-9b68f320!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Packed.Gandcrab-6520432-4
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/GandCrab.23e62317
NANO-AntivirusTrojan.Win32.Kryptik.feetig
ViRobotTrojan.Win32.GandCrab.Gen.A
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.GandCrab!8.F355 (CLOUD)
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
TACHYONRansom/W32.GandCrab
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoTrojWare.Win32.PSW.Coins.GV@7pezu9
F-SecureHeuristic.HEUR/AGEN.1103299
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.SMLA.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.956cefaa3b869720
SophosML/PE-A + Mal/Agent-AUL
SentinelOneStatic AI – Malicious PE
GDataTrojan.Ransom.GandCrab.Gen.2
JiangminTrojan.Cutwail.de
AviraHEUR/AGEN.1103299
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt
ArcabitTrojan.Ransom.GandCrab.Gen.2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRansom:Win32/GandCrab.AE
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
VBA32BScope.TrojanRansom.Wadhrama
ALYacTrojan.Ransom.GandCrab.Gen.2
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.GHVM
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
TencentMalware.Win32.Gencirc.10b3c9e5
YandexTrojan.GenAsa!2mEn4jtgKSA
IkarusTrojan-Ransom.GandCrab
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureRansomeware.CRAB.gen

How to remove BScope.TrojanRansom.Wadhrama?

BScope.TrojanRansom.Wadhrama removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment