Severity scale:  
  (99/100)

Bansomqare Wanna ransomware. How to remove? (Uninstall guide)

removal by Ugnius Kiguolis - - | Type: Ransomware

Bansomqare Wanna is ransomware that mimics infamous WannaCry

Bansomqare Wanna ransomware mimics infamous WannaCry

Bansomqare Wanna is a ransomware virus that imitates WannaCry[1] and uses Whatsapp icon. It appends .bitcoin file extension to encrypted files and generates a bitcoin2018.txt ransom note on the desktop, which urges the victim to transfer 100 USD in Bitcoins via provided Bitcoin wallet.

Name Bansomqare Wanna
Type Ransomware virus
Danger level Locks personal files, demands a ransom
File extension used .bitcoin
Ransom note bitcoin2018.txt
Related files runas.exe, whatsapp.exe, and notepad.exe
Distribution Malspam, exploit kits, hacked RPD, fake software updates, malicious ads, phishing sites
Decryptable No
Elimination Download Reimage and run a full system scan. After Bansomqare Wanna removal, follow the guide on how to decrypt files (at the end of the post)

Bansomqare Wanna ransomware is distributed in the form of runas.exe or whatsapp.exe. The file can be disclosed in spam email, hacked websites, fake software updates, and similar media that are typically used by hackers to infect users' PCs.

Once the Bansomqare Wanna payload is being executed, the virus enables the runas.exe and whatsapp.exe executables and requires administrative privileges by launching an elevated Command Prompt window. Right after that, it applies an encryption algorithm and locks documents, photos, video, database, and other personal information with the .bitcoin file extension.

Upon successful encryption, the virus generates a ransom note named Bitcoin2018.txt by creating a path C:\Users\Public\Desktop\bitcoin2018.txt. The note says:

Ooops, Your files have been encrypted!

What happened to my computer?
Your important files are encrypted.
Many of your documents, photo, video, database, and other files are no longer accessible because he have been encrypted. Maybe you are busy looking for a way to recover your files but do not waste your time. Nobody can recover your files without our decryption service.

Can I recover my files?
Sure, We guarantee that you can recover all your files safely and easily.
But you have not so enough time.
You can decrypt some of your files for free.
The bitcoin address will be saved to the “bitcoin2018.txt” file

The design of the ransom note is similar to the one used by the infamous WannaCry. It features a red background, a countdown clock on the left side, a lock icon at the top-right corner of the screen and a reference to Bitcoin wallet at the bottom. However, WannaCry does not contain a WhatsApp icon, while the Bansomqare Wanna does.

Hackers ask the victim to pay 100 USD ransom in Bitcoins with 24 hours. Before that, the victim is asked to email crooks via MildredRLewis@teleworm.us email address for more information.

The virus has been detected ate the end of March 2018. At the time of writing, no ransom has been sent to the indicated Bitcoin wallet. Nevertheless, dieviren.de[2] experts point out that the ransomware is being rolled out in phases and the rebound of attacks is expected in the nearest future.

It's not yet clear what cipher the Bansomqare ransomware uses for data encryption, but most probably it relies on the well-known AES-256 algorithm. In case the virus has already attacked your PC, we would recommend you to remove Bansomqare Wanna ransomware using Reimage, Malwarebytes MalwarebytesCombo Cleaner or Plumbytes Anti-MalwareMalwarebytes Malwarebytes security tool.

Although the Bansomqare Wanna removal will not decrypt your files, you will be able to recover at least a part of them using third-party data recovery tools. Do not pay the ransom for cybercrooks. By supporting their fraudulent activities, PC users encourage them to keep the pace and swindle people's money.

To protect yourself from the loss of personal information, make sure to create backups for the most important file types. That's one and the only trustworthy way to evade Bansomqare Wanna virus and similar attacks.

The main ransomware distribution methods

Experts haven't yet particularized the distribution method that this ransomware relies on. However, most of the Crypto-viruses are distributed via malspam campaigns.[3] Hackers steal people's email addresses and connect them to bots. This way, they can disseminate millions of fake email messages with malicious email attachments to potential ransomware victims.

This specific ransomware is closely related to runas.exe, whatsapp.exe, and Notepad.exe files. However, these files might be disguised under legitimate looking DOC files or downloads of fake software. In addition to malspam, people may get infected by crypto-malware via:

  • fake software updates;
  • hacked websites;
  • fake software updates (Java, Flash Player, Windows 10, Google Chrome, etc.);
  • exploit kits;
  • hacked remote desktop applications;
  • drive-by-download attacks, etc.

It not possible to ensure a hundred percent protection. However, those who keep the system updated and rely on a professional anti-virus program with real-time protection and updated definitions are much less prone to fall victims to ransomware attacks.

Remove Bansomqare Wanna virus

Crooks intimidate people that system's reboot will delete all locked files permanently. It's unknown whether it's true or not, but it's a fact that Bansomqare Wanna removal is a must to restore system's performance.

You won't be able to remove Bansomqare Wanna virus manually since it corrupts multiple files and registry entries that can hardly be detected without dedicated software. Thus, to wipe malicious programs and files from the system, you should scan your PC with a powerful security tool. Our top pick programs are Reimage, Malwarebytes MalwarebytesCombo Cleaner, and Plumbytes Anti-MalwareMalwarebytes Malwarebytes.

Offer
We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to remove virus damage. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
More information about this program can be found in Reimage review.

If you decided to select another anti-spyware, uninstall Reimage from your computer.
Press mentions on Reimage
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Malwarebytes.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Combo Cleaner.

To remove Bansomqare Wanna virus, follow these steps:

Remove Bansomqare Wanna using Safe Mode with Networking

Anti-virus does not work? Boot your PC into Safe Mode with Networking and try to launch it.

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove Bansomqare Wanna

    Log in to your infected account and start the browser. Download Reimage or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete Bansomqare Wanna removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove Bansomqare Wanna using System Restore

That's an alternative method to boot the system into secure environment. Follow these steps:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Bansomqare Wanna. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage and make sure that Bansomqare Wanna removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove Bansomqare Wanna from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

A free Bansomqare Wanna decryptor is not available. Once you neutralize the virus, you can try to recover locked files using third-party recovery tools.

If your files are encrypted by Bansomqare Wanna, you can use several methods to restore them:

Data Recovery Pro

Try to decrypt files using Data Recovery Tool. There's no guarantee that it will manage to crash the malicious code, but in practice it unlocked thousands of files compromised by virus, so it's worth trying. 

  • Download Data Recovery Pro;
  • Follow the steps of Data Recovery Setup and install the program on your computer;
  • Launch it and scan your computer for files encrypted by Bansomqare Wanna ransomware;
  • Restore them.

Retrieve files from the Previous Windows Version

Separate files can be decrypted by recovering their previous versions. This method is possible on Windows OS with System Restore Point created before the attack. 

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

Extract Shadow Volume Copies

The bulk of ransomware currently spreading on the Internet run a script via Command Prompt to eliminate Shadow Volume Copies. However, there are quite a lot of exceptions, so check whether these copies are still available. 

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

No decryptor

Bansomqare Wanna removal does not count as a decryptor. Experts haven't yet encoded this virus, so you should try on of the above-given methods to unlock your files. 

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Bansomqare Wanna and other ransomwares, use a reputable anti-spyware, such as Reimage, Malwarebytes MalwarebytesCombo Cleaner or Plumbytes Anti-MalwareMalwarebytes Malwarebytes

About the author

Ugnius Kiguolis
Ugnius Kiguolis - The mastermind

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Ugnius Kiguolis
About the company Esolutions

References