Ransom

Ransom:Win32/WastedLocker.B!cert removal

Malware Removal

The Ransom:Win32/WastedLocker.B!cert is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/WastedLocker.B!cert virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to delete volume shadow copies
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/WastedLocker.B!cert?


File Info:

crc32: E63D2F1E
md5: 7e34c5bd27f25a1e1d47a27702708e28
name: upload_file
sha1: fb65ea1cc1d81a17effe16ecd2d10f34975a67d8
sha256: 8dc3389d37519b24aef2bcf2a15530ea1b13ff4b98228967c9876835bdb99a01
sha512: 2b4099e3f15dfd6414c812e87c5f8cfd1926234012e6c67e71433bc4bed7c823ca6d19f8bb927d16ee8e32859b663a9cbccc890eedb3cdaebb8ec2c04784114f
ssdeep: 1536:oPCiYnre6vuRlCiJAc8Siquv40MoypmMNK9vZxNCIHVwOixDcJcJj3fjvnVAs:8ChnbuRdAcgqu4aMNKpNFkrfjvVH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/WastedLocker.B!cert also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44075510
CAT-QuickHealTrojan.Delshad
McAfeeGenericRXMG-NI!7E34C5BD27F2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Krap.lKMc
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.44075510
K7GWSpyware ( 0040f0131 )
Cybereasonmalicious.cc1d81
ArcabitTrojan.Generic.D2A089F6
InvinceaMal/Generic-R + Mal/EncPk-APV
SymantecPacked.Generic.459
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.DelShad.fbe
AlibabaTrojan:Win32/WastedLocker.a8810e46
ViRobotTrojan.Win32.Z.Wastedlocker.1213840
RisingRansom.Troldesh!8.5D1 (TFE:2:3iVpv8ZlJOL)
Ad-AwareTrojan.GenericKD.44075510
EmsisoftTrojan.GenericKD.44075510 (B)
ComodoTrojWare.Win32.Genome.cdwzw@0
F-SecureTrojan.TR/DelShad.elgks
DrWebTrojan.Encoder.32802
TrendMicroRansom.Win32.WASTEDLOCKER.AB
McAfee-GW-EditionGenericRXMG-NI!7E34C5BD27F2
MaxSecureTrojan.Malware.74826066.susgen
FireEyeGeneric.mg.7e34c5bd27f25a1e
SophosMal/EncPk-APV
SentinelOneDFI – Malicious PE
AviraTR/DelShad.elgks
MAXmalware (ai score=100)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftRansom:Win32/WastedLocker.B!cert
ZoneAlarmTrojan.Win32.DelShad.fbe
GDataTrojan.GenericKD.44075510
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.C4206425
Acronissuspicious
VBA32BScope.TrojanPSW.Racealer
ALYacTrojan.Ransom.WastedLocker
MalwarebytesTrojan.MalPack.DGI
PandaTrj/GdSda.A
ESET-NOD32Win32/Filecoder.WastedLocker.A
TrendMicro-HouseCallRansom.Win32.WASTEDLOCKER.AB
TencentWin32.Trojan.Filecoder.Ajbw
IkarusTrojan-Ransom.WastedLocker
FortinetW32/Kryptik.HDMV!tr
BitDefenderThetaGen:NN.ZexaF.34590.krX@aeW1clfi
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.2f0

How to remove Ransom:Win32/WastedLocker.B!cert?

Ransom:Win32/WastedLocker.B!cert removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment