Ransom

Ransom.BTCWare.59 information

Malware Removal

The Ransom.BTCWare.59 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.BTCWare.59 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ransom.BTCWare.59?


File Info:

crc32: 9C61CDD9
md5: 56e40d02c7ddb31612e8364ef47f6d2d
name: 56E40D02C7DDB31612E8364EF47F6D2D.mlw
sha1: d054429259786e609f7d61aa62622d13e2b9ad37
sha256: 0ddbe04a03a66e9fe99553335cc41ef6a235f52b8a3b447cd94c878650c04a07
sha512: b30dd709276797ee01b0dbafb045397da1b28a367dc33d33afc37c01ebaec4784e0edb679ae62975cb0d2581e9d685a10c4b0a29ba977f1fb903d389376ddb30
ssdeep: 12288:aER2iDU2yGPE8Yf96OJ8xgME1NjC1IGvS2A8cPMg5Emp0cr2yK:aEwis8YfSOTjjCDBA/PX6mxrNK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.BTCWare.59 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005129a91 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.BTCWare.59
CylanceUnsafe
ZillyaBackdoor.Bladabindi.Win32.19615
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Bladabindi.71a4a9ad
K7GWTrojan ( 005129a91 )
Cybereasonmalicious.2c7ddb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DPZJ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Backdoor.Win32.Bladabindi.gen
BitDefenderGen:Variant.Ransom.BTCWare.59
NANO-AntivirusTrojan.Win32.AD.eqvytu
MicroWorld-eScanGen:Variant.Ransom.BTCWare.59
TencentWin32.Backdoor.Bladabindi.Syie
Ad-AwareGen:Variant.Ransom.BTCWare.59
SophosMal/Generic-S
ComodoMalware@#1ds0shgto6js
BitDefenderThetaGen:NN.ZelphiF.34608.YGY@aKV5xBGi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PK820
McAfee-GW-EditionTrojan-FNUP!56E40D02C7DD
FireEyeGeneric.mg.56e40d02c7ddb316
EmsisoftGen:Variant.Ransom.BTCWare.59 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1121813
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Ransom.BTCWare.59
AegisLabTrojan.Win32.Bladabindi.m!c
GDataGen:Variant.Ransom.BTCWare.59
McAfeeTrojan-FNUP!56E40D02C7DD
MAXmalware (ai score=83)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.Heuristic.1006
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PK820
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.GenAsa!cVlCmVbjOUQ
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.73922510.susgen
FortinetW32/Injector.DPXV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.NjRAT.HgIASOkA

How to remove Ransom.BTCWare.59?

Ransom.BTCWare.59 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment