Ransom Trojan

Trojan-Ransom.Win32.Wanna.amet removal tips

Malware Removal

The Trojan-Ransom.Win32.Wanna.amet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Wanna.amet virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to modify desktop wallpaper
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.iuqssfsodp9ifjaposdfjhgosurijfaewrwergwea.com
www.youtube.com
ocsp.pki.goog

How to determine Trojan-Ransom.Win32.Wanna.amet?


File Info:

crc32: 692307B0
md5: e6c18ad94bb12c0f35a4533223a43e56
name: E6C18AD94BB12C0F35A4533223A43E56.mlw
sha1: 83853fc0f727de262f4252b75e4fc442e95379dd
sha256: b427e0dc86fd457ecab29c209c4a27fe32c168cea560eb8f0c4c96d5f060be69
sha512: 64578a25f2aa02628cda1df24205732df7c63a4ca975a08ef4bddbfac48367fa1b70868f5969f8bd4964c735b88fb9ec5d4fa7835da1f04e7c92f2160ef4961d
ssdeep: 12288:snmtxD3F00wOKnXmxpa4uUXVrGHGlirIN7okSf2tg8Fc1NU:lXNKnWxpa4ua9/oHMc1NU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright:
InternalName: emtec
FileVersion: 1.00
CompanyName:
LegalTrademarks:
ProductName:
ProductVersion: 1.00
OriginalFilename: emtec.exe

Trojan-Ransom.Win32.Wanna.amet also known as:

BkavW32.AIDetect.malware2
K7AntiVirusP2PWorm ( 0052362d1 )
ALYacTrojan.GenericKD.12789156
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/dark.ali1000040
K7GWP2PWorm ( 0052362d1 )
Cybereasonmalicious.94bb12
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/VB.OTF
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Wanna.amet
BitDefenderTrojan.GenericKD.12789156
NANO-AntivirusTrojan.Win32.Wanna.exirqe
MicroWorld-eScanTrojan.GenericKD.12789156
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKD.12789156
SophosMal/VB-GI
ComodoMalware@#2zdpo052o9mhn
BitDefenderThetaGen:NN.ZevbaF.34790.Vn0@a04R8ahi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.tz
FireEyeGeneric.mg.e6c18ad94bb12c0f
EmsisoftTrojan-Ransom.Filecoder (A)
AviraHEUR/AGEN.1122147
MicrosoftRansom:Win32/Wadhrama.B
ArcabitTrojan.Generic.DC325A4
AegisLabTrojan.Win32.Wanna.j!c
ZoneAlarmTrojan-Ransom.Win32.Wanna.amet
GDataTrojan.GenericKD.12789156
TACHYONRansom/W32.VB-WannaCry.1822720
McAfeeArtemis!E6C18AD94BB1
MAXmalware (ai score=96)
VBA32BScope.Trojan.Dynamer
MalwarebytesMalware.AI.3688842831
PandaTrj/GdSda.A
IkarusWorm.Win32.VB
FortinetW32/VB.GI!worm
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Wadhrama.HgIASSkA

How to remove Trojan-Ransom.Win32.Wanna.amet?

Trojan-Ransom.Win32.Wanna.amet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment