Ransom

Ransom:Win32/Wadhrama.A!rsm information

Malware Removal

The Ransom:Win32/Wadhrama.A!rsm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Wadhrama.A!rsm virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Wadhrama.A!rsm?


File Info:

crc32: AF1212AD
md5: fc65b26f64d13bc8369a013a15c60579
name: FC65B26F64D13BC8369A013A15C60579.mlw
sha1: 00954454f8e3a3d761aa050aee0bca3e20fc3dd7
sha256: f204f50deb71100ceff5d771032eb195903a6b5ca31687e5b8c31e22d9669eed
sha512: 3d179654e7a3d5ee44dbe917a057f7b72ad509ee0cbe133e016f7232001b1b714970f1a2f6de9e99cdcc4584a0752ab295240f3524afe0eb8960ac1012e69869
ssdeep: 6144:nnxwZp7GARGYOWdG2ofl+gEt6HYXBo+lG:nxoRpOM/OBE/o+
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Wadhrama.A!rsm also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Cerber.376
CAT-QuickHealRansom.Crysis.A5
Qihoo-360Win32/Trojan.Generic.HwsBueUA
ALYacTrojan.Ransom.Wallet
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00500d011 )
BitDefenderGen:Variant.Ransom.Cerber.376
K7GWTrojan ( 00500d011 )
Cybereasonmalicious.f64d13
SymantecPacked.Generic.511
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Crusis.eovoio
AegisLabTrojan.Win32.Crusis.j!c
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Ad-AwareGen:Variant.Ransom.Cerber.376
EmsisoftGen:Variant.Ransom.Cerber.376 (B)
ComodoMalware@#22non852mue3n
F-SecureHeuristic.HEUR/AGEN.1121753
DrWebTrojan.Encoder.10317
ZillyaTrojan.Crusis.Win32.323
TrendMicroRansom_CRYSIS.F117EG
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.cc
FireEyeGeneric.mg.fc65b26f64d13bc8
SophosMal/Cerber-U
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Crusis.jd
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1121753
MAXmalware (ai score=85)
Antiy-AVLTrojan[Ransom]/Win32.Crusis
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Wadhrama.A!rsm
ArcabitTrojan.Ransom.Cerber.376
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Cerber.376
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Crusis.C1960470
McAfeeArtemis!FC65B26F64D1
VBA32Hoax.Crusis
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32Win32/Filecoder.Crysis.L
TrendMicro-HouseCallRansom_CRYSIS.F117EG
TencentMalware.Win32.Gencirc.11499032
YandexTrojan.Filecoder!2ciGsm44yFY
IkarusTrojan.Win32.Filecoder
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AP.D5232!tr
BitDefenderThetaGen:NN.ZexaF.34590.mmJfaiQfY5om
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Ransom:Win32/Wadhrama.A!rsm?

Ransom:Win32/Wadhrama.A!rsm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment