Ransom

Should I remove “Ransom.WannaCrypt.A4”?

Malware Removal

The Ransom.WannaCrypt.A4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.WannaCrypt.A4 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper

How to determine Ransom.WannaCrypt.A4?


File Info:

name: AA19446AB3172AD5BED3.mlw
path: /opt/CAPEv2/storage/binaries/d37c5455c68ad16cb73a0926d01acbfb5f917ac52aab237cc0eb614ae99ceba7
crc32: 180DCE34
md5: aa19446ab3172ad5bed3992fb55864db
sha1: a1d0f009b69cc7b603c6b56997eaa07a2f58a467
sha256: d37c5455c68ad16cb73a0926d01acbfb5f917ac52aab237cc0eb614ae99ceba7
sha512: 26a2b0609fd209964c8ac205e31d9bbb27b0b56ca2620b12dfab73c84d9bf732b0a6ac00373c07eec1fda6beb2b15048eefccca9b6c826bc78e9e6192c2db3c6
ssdeep: 3072:Rmrhm1eigWcR+uiUg6p4FLlG4tlL3J+mmCeHFZxoHEo3m:REgIZiZhLlG4rQmmCa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D034C56699D3916DF3DB25BC8000DB7CB8A76E1095321F3BB684F8EC18367E4CA6511E
sha3_384: 1c1ee56cbb90b62dfd2427e017aa0da52217273ca7401e9f2e5cd3a07bf15de0a5275247194ffb7ce62ef4a705261469
ep_bytes: 558bec6aff68a8ba4100685030410064
timestamp: 2009-07-13 23:19:35

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Load PerfMon Counters
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: LODCTR.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: LODCTR.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Ransom.WannaCrypt.A4 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.WannaCrypt.A4
ALYacTrojan.Ransom.WannaCryptor.D
MalwarebytesRansom.WannaCrypt
VIPRETrojan.Win32.WannaCrypt.a (v)
K7AntiVirusTrojan ( 00571a9e1 )
K7GWTrojan ( 00571a9e1 )
Cybereasonmalicious.ab3172
VirITTrojan.Win32.WannaCry.B
CyrenW32/WannaCry.G.gen!Eldorado
SymantecRansom.Wannacry
ESET-NOD32a variant of Win32/Filecoder.WannaCryptor.D
ClamAVWin.Ransomware.WannaCry-6313787-0
KasperskyTrojan-Ransom.Win32.Wanna.c
BitDefenderTrojan.Ransom.WannaCryptor.D
NANO-AntivirusTrojan.Win32.Wanna.eovgej
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanTrojan.Ransom.WannaCryptor.D
AvastWin32:WanaCry-A [Trj]
TencentTrojan.Win32.WannaCry.d
EmsisoftTrojan.Ransom.WannaCryptor.D (B)
ComodoTrojWare.Win32.Ransom.WannaCrypt.B@719b9h
DrWebTrojan.Encoder.11432
TrendMicroRansom_WCRY.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.aa19446ab3172ad5
SophosML/PE-A + Mal/Wanna-A
JiangminTrojan.Wanna.ln
AviraHEUR/AGEN.1118500
Antiy-AVLTrojan/Generic.ASMalwS.2027829
MicrosoftRansom:MSIL/Filecoder.PK!MSR
GDataWin32.Trojan-Ransom.WannaCry.E
AhnLab-V3Trojan/Win32.WannaCryptor.R200589
McAfeeRansom-WannaCry!AA19446AB317
TACHYONRansom/W32.Wanna.245760
VBA32TrojanRansom.Wanna
TrendMicro-HouseCallRansom_WCRY.SM
YandexTrojan.GenAsa!DkX5FxEFGvQ
IkarusTrojan-Ransom.WannaCry
eGambitUnsafe.AI_Score_100%
FortinetW32/Wanna.C!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34182.pq0@aOm@Elgi
AVGWin32:WanaCry-A [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Ransom.Wanna.d

How to remove Ransom.WannaCrypt.A4?

Ransom.WannaCrypt.A4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment