Ransom Trojan

About “Trojan-Ransom.Win32.Wasted.n” infection

Malware Removal

The Trojan-Ransom.Win32.Wasted.n is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Wasted.n virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Wasted.n?


File Info:

crc32: B0BCF431
md5: ecb00e9a61f99a7d4c90723294986bbc
name: ECB00E9A61F99A7D4C90723294986BBC.mlw
sha1: be59c867da75e2a66b8c2519e950254f817cd4ad
sha256: 8897db876553f942b2eb4005f8475a232bafb82a50ca7761a621842e894a3d80
sha512: 9dee79827d865de41a63962b419eed7e1f9610ff27f00f8b7b2b9f51e905d5db907d310da590d8f1a11ac88e549373edf39bffdb44d1b205728f1b5e0a43aa5e
ssdeep: 1536:d2SYM6dDF+WO8Rh51yXjk2JqdT8LONUeCSC0eWNF:dLYndDg8v51cZoHNF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Wasted.n also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0054f96e1 )
LionicTrojan.Win32.Wasted.trtA
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31904
CAT-QuickHealRansom.WSLocker.S14539967
McAfeeRansom-Wasted
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.15058
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/DelShad.16a8c73b
K7GWSpyware ( 0054f96e1 )
Cybereasonmalicious.a61f99
CyrenW32/Trojan.XAEM-2131
SymantecRansom.WastedLocker
ESET-NOD32a variant of Win32/Filecoder.WastedLocker.A
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Wasted.n
BitDefenderGen:Variant.Razy.787991
NANO-AntivirusTrojan.Win32.DelShad.ikbtft
ViRobotTrojan.Win32.S.Ransom.57344.F
MicroWorld-eScanGen:Variant.Razy.787991
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Razy.787991
SophosML/PE-A + Troj/Agent-BEZX
ComodoMalware@#27gly5zu0ambg
BitDefenderThetaAI:Packer.4B82F4AF1E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.WASTEDLOCKER.YAAF-A
McAfee-GW-EditionBehavesLike.Win32.Dropper.qc
FireEyeGeneric.mg.ecb00e9a61f99a7d
EmsisoftGen:Variant.Razy.787991 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.DelShad.xv
WebrootW32.Ransom.Wastedlocker
AviraTR/AD.Ursnif.crwrl
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.308E2A0
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/DelShad
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Variant.Razy.787991
TACHYONRansom/W32.WastedLocker.57344
AhnLab-V3Malware/Win32.Generic.C4139121
VBA32BScope.Trojan.DelShad
MAXmalware (ai score=100)
MalwarebytesRansom.BinADS
PandaTrj/CI.A
TrendMicro-HouseCallRansom.Win32.WASTEDLOCKER.YAAF-A
RisingTrojan.Generic@ML.89 (RDML:kbOBz8BXxTHs1LzxwbfSFg)
YandexTrojanSpy.Ursnif!imY8FkMVmOs
IkarusTrojan-Ransom.WastedLocker
MaxSecureTrojan.Malware.103306555.susgen
FortinetW32/DelShad.CR!tr.ransom
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Wasted.n?

Trojan-Ransom.Win32.Wasted.n removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment