Ransom

How to remove “Ransom.WSLocker.S15413983”?

Malware Removal

The Ransom.WSLocker.S15413983 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.WSLocker.S15413983 virus can do?

  • At least one process apparently crashed during execution
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.WSLocker.S15413983?


File Info:

crc32: A6CF80A4
md5: eb86699181894931833816e860ab279d
name: upload_file
sha1: e98d1319d2614debebeeabc26616d327950f699e
sha256: 06e3e56153ca25cb9790495f0768e9b615e088f9241ac7f3b974f2e9cd97bd21
sha512: 9b567fbca1cd9720c86bd848a49dc8aeda47104d06be7c4d7189a6a7ec6956c41ee5c40aac49f90067e7ab2e7b65078197b9f9d6c7a5e2c1c52b9ab971a6c714
ssdeep: 1536:Zjq8DHPkaRJPLhxLHQnp5+GZnrggRixqRal8fBcvirzgDG5fWEQF2z:N5bMR5/VrYqgyhWEks
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.WSLocker.S15413983 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.Imps.1
CAT-QuickHealRansom.WSLocker.S15413983
McAfeeGenericRXAA-AA!EB8669918189
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Heur.Ransom.Imps.1
ArcabitTrojan.Ransom.Imps.1
InvinceaML/PE-A
SymantecML.Attribute.HighConfidence
APEXMalicious
RisingRansom.GanWaste!8.11E8C (TFE:5:UlZk8UgDiFI)
Ad-AwareGen:Heur.Ransom.Imps.1
EmsisoftGen:Heur.Ransom.Imps.1 (B)
F-SecureTrojan.TR/ATRAPS.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.kh
FireEyeGeneric.mg.eb86699181894931
SentinelOneDFI – Suspicious PE
AviraTR/ATRAPS.Gen
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.C!ml
GDataGen:Heur.Ransom.Imps.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransom.C4170354
VBA32BScope.Trojan.DelShad
ALYacGen:Heur.Ransom.Imps.1
MalwarebytesRansom.BinADS
ESET-NOD32a variant of Win32/Filecoder.WastedLocker.A
IkarusTrojan-Ransom.WastedLocker
eGambitUnsafe.AI_Score_89%
BitDefenderThetaAI:Packer.476FC8421E
AVGWin32:Dh-A [Heur]
Cybereasonmalicious.181894
AvastWin32:Dh-A [Heur]
Qihoo-360HEUR/QVM20.1.EFBF.Malware.Gen

How to remove Ransom.WSLocker.S15413983?

Ransom.WSLocker.S15413983 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment