Ransom

Ransom:Win32/WannaCrypt!rfn removal guide

Malware Removal

The Ransom:Win32/WannaCrypt!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/WannaCrypt!rfn virus can do?

    How to determine Ransom:Win32/WannaCrypt!rfn?

    
    

    File Info:

    crc32: 6C1E6225
    md5: 0524579c38b45ce3f90865a91d4318a4
    name: tmpymrcyn3_
    sha1: 8e83ecec5282b97d546337b7f38730d11239095c
    sha256: 84b1d8023123d575eccd1b917d93a5ca9d70e41dcc14c88a6a6b21ecae7bd57d
    sha512: 57515462be1e8c8a9806cb65690b0514997ebe7435a10e6f4359fa3144495a12fc403dcae940cc43ac17dfe4e48911cae20fde866e715cdcd28ab94057057440
    ssdeep: 6144:+cQa4X1Bm+1tM5RwTs/dSXj84mRXPemxdBlPvLzLG:enX1Bmb5RwBG4mxdB9HG
    type: PE32 executable (GUI) Intel 80386, for MS Windows

    Version Info:

    0: [No Data]

    Ransom:Win32/WannaCrypt!rfn also known as:

    MicroWorld-eScanTrojan.GenericKD.5057841
    CAT-QuickHealRansom.WannaCrypt.A4
    McAfeeRansom-WannaCry!0524579C38B4
    ZillyaTrojan.GenericKD.Win32.143973
    SUPERAntiSpywareTrojan.Agent/Gen-Malagent
    SangforMalware
    AlibabaRansom:Win32/Wanna.f8e141b1
    CrowdStrikewin/malicious_confidence_100% (W)
    TrendMicroRansom_WCRY.SM4
    F-ProtW32/Trojan2.PUQT
    SymantecTrojan.Gen.2
    ESET-NOD32Win32/NukeSped.CJ
    TrendMicro-HouseCallRansom_WCRY.SM4
    Paloaltogeneric.ml
    ClamAVWin.Trojan.Agent-1388727
    GDataTrojan.GenericKD.5057841
    KasperskyTrojan-Ransom.Win32.Wanna.ah
    BitDefenderTrojan.GenericKD.5057841
    ViRobotTrojan.Win32.S.WannaCry.307200
    AvastWin32:Malware-gen
    RisingRansom.WanaCrypt!1.AAF9 (CLOUD)
    Ad-AwareTrojan.GenericKD.5057841
    SophosMal/Wanna-A
    ComodoMalware@#bpb5vyi0g5ra
    DrWebTrojan.Encoder.10718
    Invinceaheuristic
    McAfee-GW-EditionBehavesLike.Win32.RansomWannaCry.fc
    Trapminemalicious.moderate.ml.score
    FireEyeGeneric.mg.0524579c38b45ce3
    EmsisoftTrojan.GenericKD.5057841 (B)
    APEXMalicious
    CyrenW32/Trojan.TNJR-5779
    JiangminTrojan.WanaCry.ab
    eGambitTrojan.Generic
    MAXmalware (ai score=100)
    Antiy-AVLTrojan/Win32.BTSGeneric
    Endgamemalicious (high confidence)
    ArcabitTrojan.Generic.D4D2D31
    AegisLabTrojan.Win32.Wanna.toNO
    ZoneAlarmTrojan-Ransom.Win32.Wanna.ah
    MicrosoftRansom:Win32/WannaCrypt!rfn
    SentinelOneDFI – Malicious PE
    AhnLab-V3Trojan/Win32.WannaCryptor.R200677
    Acronissuspicious
    VBA32BScope.TrojanRansom.Wanna
    ALYacTrojan.GenericKD.5057841
    TACHYONRansom/W32.WannaCry.307200.E
    TencentTrojan.Win32.WannaCry.k
    YandexTrojan.Filecoder!LQDLAGMuHnk
    IkarusTrojan-Ransom.WannaCry
    MaxSecureTrojan.Malware.10986119.susgen
    FortinetW32/Generic.AP.D4936!tr
    WebrootW32.Ransom.Gen
    AVGWin32:Malware-gen
    Cybereasonmalicious.c38b45
    PandaTrj/CI.A
    Qihoo-360Win32/Worm.WannaCrypt.K

    How to remove Ransom:Win32/WannaCrypt!rfn?

    Ransom:Win32/WannaCrypt!rfn removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment