Ransom Trojan

Trojan-Ransom.Win32.Bitman.aduw removal guide

Malware Removal

The Trojan-Ransom.Win32.Bitman.aduw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Bitman.aduw virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Connects to Tor Hidden Services through a Tor gateway
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
7tno4hib47vlep5o.tor2web.org
7tno4hib47vlep5o.tor2web.blutmagie.de
7tno4hib47vlep5o.tor2web.fi

How to determine Trojan-Ransom.Win32.Bitman.aduw?


File Info:

crc32: E1E792DF
md5: 0e361417c0d9daa904cde171aad4eed7
name: 0E361417C0D9DAA904CDE171AAD4EED7.mlw
sha1: 5b14b5db68e9696d76cd10774527a5d784c43aca
sha256: b3b948b50d67e877ffc7ad83028ac63507a2633f621494b2382a80cb1c240f5a
sha512: f0eab8dac04e33f40a49bd5d4c7f573f27e29cfe10da7f4a9fc92500df6b93a0a3b386dc0b7e632c066fe4dafba31a0f54d4562f15bdc587ac742bf6039dd3ed
ssdeep: 24576:EjrCAaq9P7dFhJ9Fl09Y76NKspaenuIpBYzqej02lsSYK/vBvihqH0pJYXMm3Z9:0sK4soBY
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Bitman.aduw also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.31059773
FireEyeGeneric.mg.0e361417c0d9daa9
ALYacTrojan.GenericKD.31059773
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.31059773
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaCO.34590.0nW@a4QGtac
SymantecTrojan Horse
APEXMalicious
KasperskyTrojan-Ransom.Win32.Bitman.aduw
NANO-AntivirusTrojan.Win32.Bitman.fffcjb
RisingRansom.Tescrypt!8.3AF (CLOUD)
Ad-AwareTrojan.GenericKD.31059773
EmsisoftTrojan.GenericKD.31059773 (B)
McAfee-GW-EditionBehavesLike.Win32.Downloader.tm
SophosMal/Generic-S
IkarusTrojan-Ransom.TeslaCrypt
MicrosoftRansom:Win32/Tescrypt.A
ArcabitTrojan.Generic.D1D9EF3D
ZoneAlarmTrojan-Ransom.Win32.Bitman.aduw
GDataTrojan.GenericKD.31059773
McAfeeArtemis!0E361417C0D9
MalwarebytesRansom.TeslaCrypt
TencentWin32.Trojan.Bitman.Glq
YandexTrojan.GenAsa!+jdaMPWlbxg
FortinetW32/Bitman.ADUW!tr
Cybereasonmalicious.7c0d9d
PandaTrj/GdSda.A

How to remove Trojan-Ransom.Win32.Bitman.aduw?

Trojan-Ransom.Win32.Bitman.aduw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment