Ransom Trojan

Trojan.Ransom.BSA (file analysis)

Malware Removal

The Trojan.Ransom.BSA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BSA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan.Ransom.BSA?


File Info:

crc32: 0325335A
md5: 1a59b84c3f683f640cb10607242647f0
name: 1A59B84C3F683F640CB10607242647F0.mlw
sha1: 8f46d4e6c7d0326fc3a1d971e56a42bcd6cee561
sha256: 38def2fe9407b3fc72618fc609142bcb2f0289fa441feba85466eef5fc9bf485
sha512: fce7b1f1806b8c18520e50fc4dd4d3ba1c29d499f121904b5abfd53fffb28d4fbde06a671eba0876c0d9e6634927a846f36a6dfcb5c409d11e054c9dc60b9303
ssdeep: 12288:5BewdeQ63LkbZzJ52fDdwuRRxjdWVyPlHKxK3KD8nqi6b0jEAR3+Lb:5Qw/6b2ZzJ52fDdwuRRxjdWVyPlSK3K
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.BSA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00528e801 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.12815
CynetMalicious (score: 100)
CAT-QuickHealSoftwareBundler.Prepscram.AL7
ALYacTrojan.Ransom.BSA
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2535901
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/StartSurf.997a5144
K7GWTrojan ( 0050e6d61 )
Cybereasonmalicious.c3f683
CyrenW32/S-e54b850c!Eldorado
SymantecTrojan.Randsom.A
ESET-NOD32a variant of Win32/Kryptik.FSPD
APEXMalicious
AvastWin32:Evo-gen [Susp]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.akio
BitDefenderTrojan.Ransom.BSA
NANO-AntivirusTrojan.Win32.Vittalia.eqrtst
MicroWorld-eScanTrojan.Ransom.BSA
TencentTrojan.Win32.StartSurf.a
Ad-AwareTrojan.Ransom.BSA
SophosMal/Generic-S
ComodoApplication.Win32.IStartSurf.BS@7lng48
BitDefenderThetaGen:NN.ZexaF.34608.PCW@a8bmuGdi
VIPREAdware.Win32.StartSurf
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.1a59b84c3f683f64
EmsisoftTrojan.Ransom.BSA (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1103302
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.Ransom.BSA
AegisLabAdware.Win32.StartSurf.2!c
ZoneAlarmnot-a-virus:AdWare.Win32.StartSurf.akio
GDataTrojan.Ransom.BSA
AhnLab-V3PUP/Win32.StartSurf.C2032155
Acronissuspicious
McAfeeGenericRXBX-QZ!1A59B84C3F68
MAXmalware (ai score=100)
VBA32BScope.AdWare.StartSurf
MalwarebytesGeneric.Trojan.Bundler.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.ABF5 (CLOUD)
IkarusTrojan.Win32.Crypt
FortinetW32/Generic.AP.10942E!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
Qihoo-360Win32/Adware.Generic.HgIASOkA

How to remove Trojan.Ransom.BSA?

Trojan.Ransom.BSA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment