Ransom

What is “Generic.Ransom.RaRans.35604622”?

Malware Removal

The Generic.Ransom.RaRans.35604622 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.RaRans.35604622 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
2no.co
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
r3.o.lencr.org

How to determine Generic.Ransom.RaRans.35604622?


File Info:

crc32: 4069B74A
md5: 8f94c21eefa78417d786a1e5d4fb17e9
name: 8F94C21EEFA78417D786A1E5D4FB17E9.mlw
sha1: 35275a8f1a36ceca6e8324bf49c4406cb237aa62
sha256: c58a9b49ce1520701def4694a226a92c08c94a559fe76166bbb56ae35e8663be
sha512: f55adfac55f75dfbf0b52b029824314ffb0acd0cb1b61fd458287808fd323b4f1e72c678e5e02601ddf9fd18ef65106c45faba6b07bfe0ac0ae4ca4863117668
ssdeep: 1536:7R6CWAxVx1IoGTtD5Nz47Idcf7gYE/J0nj4LXn2:YCLNKVz48dcDgfJE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.RaRans.35604622 also known as:

K7AntiVirusTrojan ( 00536e861 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGeneric.Ransom.RaRans.35604622
CylanceUnsafe
ZillyaTrojan.Cryptor.Win32.320
SangforRansom.Win32.Cryptor.ccx
AlibabaRansom:Win32/Cryptor.9a6d075c
K7GWTrojan ( 00536e861 )
Cybereasonmalicious.eefa78
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NRB
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Cryptor.ccx
BitDefenderGeneric.Ransom.RaRans.35604622
NANO-AntivirusTrojan.Win32.Cryptor.fkswyl
MicroWorld-eScanGeneric.Ransom.RaRans.35604622
TencentWin32.Trojan.Cryptor.Eerk
Ad-AwareGeneric.Ransom.RaRans.35604622
SophosGeneric PUA DF (PUA)
ComodoMalware@#1n83nbsp0goe7
BitDefenderThetaAI:Packer.9347496A1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Autorun.kh
FireEyeGeneric.mg.8f94c21eefa78417
EmsisoftGeneric.Ransom.RaRans.35604622 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Cryptor.jn
AviraTR/FileCoder.lfdlb
Antiy-AVLTrojan/Generic.ASMalwS.29B25BC
MicrosoftTrojan:Win32/Occamy.C
GDataGeneric.Ransom.RaRans.35604622
AhnLab-V3Malware/Win32.Generic.C2940779
McAfeeArtemis!8F94C21EEFA7
MAXmalware (ai score=82)
VBA32BScope.TrojanRansom.Cryptor
PandaTrj/GdSda.A
YandexTrojan.Cryptor!B6HrATSam88
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.NRB!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cryptor.HxQBEpsA

How to remove Generic.Ransom.RaRans.35604622?

Generic.Ransom.RaRans.35604622 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment