Ransom Trojan

Trojan-Ransom.Win32.Wanna removal guide

Malware Removal

The Trojan-Ransom.Win32.Wanna is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Wanna virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Wanna?


File Info:

crc32: 5451F149
md5: cf7645b5c1e3b534c48a6767efcaaa51
name: CF7645B5C1E3B534C48A6767EFCAAA51.mlw
sha1: 88f94a412b75e5e5b0e5c4f00e3ee0356a63746d
sha256: c2336a135878814b7b9b82146879a4ee8910e0a7e540415cb3716e1f62c1ea41
sha512: e9bfade618c71ce69eb39ea94dcd282268d1647893d73adb2a2dcbb22e69ce661bd89064877d9aec14c8e870d1b0c425dedd6c01920d05247aeadee3ab19bf0a
ssdeep: 6144:Ds90vzqFySKS0S4C1mnnWiziYjdeti5/2:yQrBarmnnWiziIeIl2
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Wanna also known as:

K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.FrauDrop.gen
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/Formbook.75c90c8c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.12b75e
CyrenW32/Injector.AIC.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Formbook.AA
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Wanna.gen
BitDefenderTrojan.GenericKD.46334116
MicroWorld-eScanTrojan.GenericKD.46334116
Ad-AwareTrojan.GenericKD.46334116
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.cf7645b5c1e3b534
EmsisoftTrojan.GenericKD.46334116 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Swotter.mshhm
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
AegisLabTrojan.Win32.Noon.l!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Wanna.gen
GDataWin32.Trojan-Stealer.FormBook.45RT1Y
AhnLab-V3Trojan/Win.Generic.C4484616
McAfeeArtemis!CF7645B5C1E3
MAXmalware (ai score=85)
VBA32Trojan.Wacatac
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00EL21
IkarusWin32.SuspectCrc
FortinetNSIS/Injector.AKV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Wanna?

Trojan-Ransom.Win32.Wanna removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment