Ransom Trojan

Trojan-Ransom.Win32.Wasted.f removal guide

Malware Removal

The Trojan-Ransom.Win32.Wasted.f is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Wasted.f virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Wasted.f?


File Info:

crc32: 3EBE3850
md5: 572fea5f025df78f2d316216fbeee52e
name: 572FEA5F025DF78F2D316216FBEEE52E.mlw
sha1: 91b2bf44b1f9282c09f07f16631deaa3ad9d956d
sha256: 5cd04805f9753ca08b82e88c27bf5426d1d356bb26b281885573051048911367
sha512: eb238272227c5825477ff1e37dc4f7e467665049d4db5649fff59c39d7745e88b06234d6d1218c05c802e33e21577f9d4a533cb9e23ebe6fb09654f97759c187
ssdeep: 1536:oqRaSoNRhXeFFIEuz29JfZsIzYJerU+zjqFeKUO1z1gZCHW8LiLrXz4HE7bhj5Bs:oqRa/fhGFIZyJfZsqCGez5W1Ekxj5+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: This is GNU Software copyright Josh Karlin
InternalName: Launchy.exe
FileVersion: 1.0.0
CompanyName: Code Jelly
ProductName: Launchy
ProductVersion: 2.0
FileDescription: Launchy
OriginalFilename: Launchy.exe
Translation: 0x0409 0x04e4

Trojan-Ransom.Win32.Wasted.f also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056994f1 )
LionicHacktool.Win32.Krap.lKMc
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31951
CAT-QuickHealRansom.WSLocker.S15564067
McAfeeRansom-Wasted
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2052505
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Wasted.97f16ae1
K7GWTrojan ( 0056994f1 )
Cybereasonmalicious.f025df
CyrenW32/Trojan.NQEH-0584
SymantecRansom.WastedLocker
ESET-NOD32Win32/Filecoder.WastedLocker.A
ZonerTrojan.Win32.92368
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Wasted.f
BitDefenderTrojan.GenericKD.34029721
NANO-AntivirusTrojan.Win32.Encoder.hlircz
ViRobotTrojan.Win32.S.Ransom.1076112
MicroWorld-eScanTrojan.GenericKD.34029721
TencentMalware.Win32.Gencirc.11abf55a
Ad-AwareTrojan.GenericKD.34029721
SophosMal/Generic-R + Mal/EncPk-APV
ComodoMalware@#1yix59upfx9lj
BitDefenderThetaGen:NN.ZexaF.34058.bn1@aKevf5pi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.WASTEDLOCKER.YAAF-A
McAfee-GW-EditionRansom-Wasted
FireEyeGeneric.mg.572fea5f025df78f
EmsisoftTrojan.GenericKD.34029721 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.DelShad.zq
WebrootW32.Ransom.Wastedlocker
AviraTR/Crypt.Agent.ujiiq
Antiy-AVLTrojan/Generic.ASCommon.1BE
MicrosoftRansom:Win32/WastedLocker.WT!MTB
ArcabitTrojan.Generic.D2074099
GDataWin32.Trojan-Ransom.Wasted.K4RUM5
TACHYONRansom/W32.WastedLocker.1076112
AhnLab-V3Trojan/Win32.Agent.R341646
VBA32BScope.TrojanRansom.Shade
MAXmalware (ai score=100)
MalwarebytesRansom.BinADS
PandaTrj/WLT.F
TrendMicro-HouseCallRansom.Win32.WASTEDLOCKER.YAAF-A
RisingTrojan.Generic@ML.100 (RDML:d5hr52RSvS4IZ/SHP2P3pw)
YandexTrojan.Kryptik!HitBlJ3ec3o
IkarusTrojan-Ransom.WastedLocker
MaxSecureTrojan.Malware.102356251.susgen
FortinetW32/QBOT.CC!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.QakBot.HxQBEpsA

How to remove Trojan-Ransom.Win32.Wasted.f?

Trojan-Ransom.Win32.Wasted.f removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment