Categories: RansomTrojan

Trojan-Ransom.Win32.Bitman.aduw removal guide

The Trojan-Ransom.Win32.Bitman.aduw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Bitman.aduw virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Connects to Tor Hidden Services through a Tor gateway
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
7tno4hib47vlep5o.tor2web.org
7tno4hib47vlep5o.tor2web.blutmagie.de
7tno4hib47vlep5o.tor2web.fi

How to determine Trojan-Ransom.Win32.Bitman.aduw?


File Info:

crc32: E1E792DFmd5: 0e361417c0d9daa904cde171aad4eed7name: 0E361417C0D9DAA904CDE171AAD4EED7.mlwsha1: 5b14b5db68e9696d76cd10774527a5d784c43acasha256: b3b948b50d67e877ffc7ad83028ac63507a2633f621494b2382a80cb1c240f5asha512: f0eab8dac04e33f40a49bd5d4c7f573f27e29cfe10da7f4a9fc92500df6b93a0a3b386dc0b7e632c066fe4dafba31a0f54d4562f15bdc587ac742bf6039dd3edssdeep: 24576:EjrCAaq9P7dFhJ9Fl09Y76NKspaenuIpBYzqej02lsSYK/vBvihqH0pJYXMm3Z9:0sK4soBYtype: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Bitman.aduw also known as:

Bkav W32.AIDetect.malware2
MicroWorld-eScan Trojan.GenericKD.31059773
FireEye Generic.mg.0e361417c0d9daa9
ALYac Trojan.GenericKD.31059773
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.GenericKD.31059773
K7GW Riskware ( 0040eff71 )
BitDefenderTheta Gen:NN.ZexaCO.34590.0nW@a4QGtac
Symantec Trojan Horse
APEX Malicious
Kaspersky Trojan-Ransom.Win32.Bitman.aduw
NANO-Antivirus Trojan.Win32.Bitman.fffcjb
Rising Ransom.Tescrypt!8.3AF (CLOUD)
Ad-Aware Trojan.GenericKD.31059773
Emsisoft Trojan.GenericKD.31059773 (B)
McAfee-GW-Edition BehavesLike.Win32.Downloader.tm
Sophos Mal/Generic-S
Ikarus Trojan-Ransom.TeslaCrypt
Microsoft Ransom:Win32/Tescrypt.A
Arcabit Trojan.Generic.D1D9EF3D
ZoneAlarm Trojan-Ransom.Win32.Bitman.aduw
GData Trojan.GenericKD.31059773
McAfee Artemis!0E361417C0D9
Malwarebytes Ransom.TeslaCrypt
Tencent Win32.Trojan.Bitman.Glq
Yandex Trojan.GenAsa!+jdaMPWlbxg
Fortinet W32/Bitman.ADUW!tr
Cybereason malicious.7c0d9d
Panda Trj/GdSda.A

How to remove Trojan-Ransom.Win32.Bitman.aduw?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

About “Malware.AI.4109823579” infection

The Malware.AI.4109823579 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

About “PUA:Win32/IminentToolbar” infection

The PUA:Win32/IminentToolbar is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Malware.AI.1686126144 removal guide

The Malware.AI.1686126144 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Malware.AI.3672090432 information

The Malware.AI.3672090432 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Should I remove “Malware.AI.4241069872”?

The Malware.AI.4241069872 is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

Trojan:Win32/Remcos!pz (file analysis)

The Trojan:Win32/Remcos!pz is considered dangerous by lots of security experts. When this infection is active,…

32 mins ago