Ransom Trojan

Trojan-Ransom.Win32.Wasted.vho (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Wasted.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Wasted.vho virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to delete volume shadow copies
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Wasted.vho?


File Info:

crc32: 88BB0733
md5: 13e623cdfb75d99ea7e04c6157ca8ae6
name: 13E623CDFB75D99EA7E04C6157CA8AE6.mlw
sha1: f25f0b369a355f30f5e11ac11a7f644bcfefd963
sha256: aa05e7a187ddec2e11fc1c9eafe61408d085b0ab6cd12caeaf531c9dca129772
sha512: ea6b5c882a5298e527be1f3c40cc6d75c56453dd0111d7e9818c28fa7ec32feb19f17cab9a9e49eb0ab9f3a987f7dcc5cadfea7ae99a996f174b0a89e674f421
ssdeep: 1536:LqRaSoNRhXeFFIEuz29JfZsIzYJerJ0+B4jPOnXYY8ZCHPcXz4HE7bhjYWLc:LqRa/fhGFIZyJfZsqCK62rTPoEkxjc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: This is GNU Software copyright Josh Karlin
InternalName: Launchy.exe
FileVersion: 1.0.0
CompanyName: Code Jelly
ProductName: Launchy
ProductVersion: 2.0
FileDescription: Launchy
OriginalFilename: Launchy.exe
Translation: 0x0409 0x04e4

Trojan-Ransom.Win32.Wasted.vho also known as:

K7AntiVirusTrojan ( 00569bbf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31951
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaBackdoor.Mokes.Win32.2309
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Kryptik.37c0e849
K7GWTrojan ( 00569bbf1 )
Cybereasonmalicious.dfb75d
CyrenW32/Trojan.FMYK-1577
SymantecRansom.WastedLocker
ESET-NOD32Win32/Filecoder.WastedLocker.A
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan-Ransom.Win32.Wasted.vho
BitDefenderGen:Heur.Mint.Regotet.1
NANO-AntivirusTrojan.Win32.Encoder.hmangd
ViRobotTrojan.Win32.S.Agent.1127312
MicroWorld-eScanGen:Heur.Mint.Regotet.1
TencentWin32.Trojan.Falsesign.Dzkg
Ad-AwareGen:Heur.Mint.Regotet.1
SophosMal/Generic-R + Mal/EncPk-APV
ComodoMalware@#5md0t6jb441s
BitDefenderThetaGen:NN.ZexaF.34628.er1@aOkJFUgi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.QAKBOT.SMTHA.hp
McAfee-GW-EditionRansom-Wasted
FireEyeGeneric.mg.13e623cdfb75d99e
EmsisoftGen:Heur.Mint.Regotet.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Mokes.clx
WebrootW32.Ransom.Wastedlocker
AviraTR/Crypt.Agent.dsidt
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Gozi.RA!MTB
GDataGen:Heur.Mint.Regotet.1
TACHYONRansom/W32.WastedLocker.1127312
AhnLab-V3Trojan/Win32.Agent.R341646
McAfeeRansom-Wasted
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesRansom.BinADS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.QAKBOT.SMTHA.hp
RisingRansom.Wasted!8.11E91 (CLOUD)
YandexTrojan.Kryptik!sqgjSXAFskM
IkarusTrojan-Ransom.WastedLocker
MaxSecureTrojan.Malware.74662225.susgen
FortinetW32/Kryptik.HDMT!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HxQB5H8A

How to remove Trojan-Ransom.Win32.Wasted.vho?

Trojan-Ransom.Win32.Wasted.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment