Ransom Trojan

Trojan-Ransom.Win32.Wanna.amfp malicious file

Malware Removal

The Trojan-Ransom.Win32.Wanna.amfp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Wanna.amfp virus can do?

  • Executable code extraction
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
www.ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.com
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Wanna.amfp?


File Info:

crc32: B40717E3
md5: dc422566685b49e7c11aee11a1b736d0
name: DC422566685B49E7C11AEE11A1B736D0.mlw
sha1: 8103afb7a86827839a2595514080e06a2c4dff2b
sha256: 9db41efae6dfbe594799bde177cd7b35966d1b56bafc8778af27a62332362cad
sha512: 72480ae54b5da9e46b08d9e1c482d0b2d8ee7a2bdd2ba86062d4e52393f954d854bbd0211fe95442d0407c5a3013c97ece168c9ea1d97f13f091090c219c5dfb
ssdeep: 1536:9CigjPCQQm5BVURBVMYiASl3elVtmywZ3eSfMNg5Ig:9C7PCQQm5gRBVFiAS3eV4ywZuSfMNgn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright:
InternalName: Install4
FileVersion: 1.00
CompanyName:
LegalTrademarks:
ProductName:
ProductVersion: 1.00
OriginalFilename: Install4.exe

Trojan-Ransom.Win32.Wanna.amfp also known as:

BkavW32.AIDetect.malware2
K7AntiVirusP2PWorm ( 0052362d1 )
DrWebBACKDOOR.Trojan
CylanceUnsafe
ZillyaTrojan.Wanna.Win32.903
SangforWorm.Win32.VB.OTF
AlibabaTrojan:Win32/dark.ali1000040
K7GWP2PWorm ( 0052362d1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/VB.OTF
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Wanna.amfp
NANO-AntivirusTrojan.Win32.Wanna.exwdtq
TencentWin32.Trojan.Ransomware.Auto
SophosML/PE-A + Mal/VB-GI
ComodoMalware@#32rdwlz4yv2kv
BitDefenderThetaGen:NN.ZevbaF.34690.gm0@aq3bPLhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.cm
FireEyeGeneric.mg.dc422566685b49e7
JiangminTrojan.Wanna.dx
AviraBDS/Agent.xapkd
Antiy-AVLTrojan/Generic.ASMalwS.2459D5B
MicrosoftRansom:Win32/Wadhrama.B
AegisLabTrojan.Win32.Wanna.u!c
McAfeeArtemis!DC422566685B
MAXmalware (ai score=99)
VBA32TrojanRansom.Wanna
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
RisingRansom.Wanna!8.E7B2 (CLOUD)
YandexTrojan.Wanna!CGB2Tti0d7A
IkarusWorm.Win32.VB
FortinetW32/VB.GI
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Wanna.amfp?

Trojan-Ransom.Win32.Wanna.amfp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment