Ransom

Mal/Ransom-AI malicious file

Malware Removal

The Mal/Ransom-AI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Ransom-AI virus can do?

  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Mal/Ransom-AI?


File Info:

crc32: 320DDB5B
md5: c23884a8b9e0ecd347bf0655fd24e031
name: winlocker_606072.exe
sha1: 8302c4fbaab61a0ba74d1404d2e5a5ef013f2776
sha256: d3f987cc65e2a2b3072a054b9b557d148c44f1b2eb766fcd8e72585e81a89432
sha512: b715b2136286a09286923e76e76fea1a32da3001ffab400c487619f98bf88771458a3454d601098dc665c36c07dc06d5a6195753cf36a6556ef5c8164514dbd2
ssdeep: 12288:thxp3lZnT9bDPNIEjgVtYmppppppppppppppppppppppppppqyZ3U7u6jvnXRsLe:tJlh9bDFBjgVtYhyZyfhxAE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Ransom-AI also known as:

MicroWorld-eScanTrojan.GenericKD.31356460
CMCTrojan-Ransom.Win32.Birele!O
CAT-QuickHealRansom.Weenloc.A8
ALYacTrojan.GenericKD.31356460
AegisLabTrojan.Win32.Blocker.4!c
BitDefenderTrojan.GenericKD.31356460
K7GWTrojan ( 0039911e1 )
K7AntiVirusTrojan ( 0039911e1 )
TrendMicroRansom_WINLOCK.SM
BaiduWin32.Trojan.LockScreen.b
NANO-AntivirusTrojan.Win32.Fullscreen.crnep
CyrenW32/Trojan.GDVD-7096
SymantecTrojan.Ransomlock
TotalDefenseWin32/Ransom.BAM
TrendMicro-HouseCallRansom_WINLOCK.SM
Paloaltogeneric.ml
GDataTrojan.GenericKD.31356460
KasperskyTrojan-Ransom.Win32.Blocker.jzec
ViRobotTrojan.Win32.Z.Fullscreen.563978
RisingTrojan.Win32.Weenloc.a (CLOUD)
Ad-AwareTrojan.GenericKD.31356460
EmsisoftTrojan.GenericKD.31356460 (B)
ComodoMalware@#37t4xvab89oqt
F-SecureDropper.DR/Delphi.Gen4
DrWebTrojan.Winlock.3333
ZillyaTrojan.Fullscreen.Win32.36
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.hc
Trapminemalicious.high.ml.score
SophosMal/Ransom-AI
F-ProtW32/Trojan2.OAEZ
JiangminTrojan/Fullscreen.ak
AviraDR/Delphi.Gen4
Antiy-AVLTrojan[Ransom]/Win32.PornoAsset.cioy
KingsoftVIRUS_UNKNOWN
ArcabitTrojan.Generic.D1DE762C
ZoneAlarmTrojan-Ransom.Win32.Blocker.jzec
MicrosoftRansom:Win32/Weenloc.A
McAfeeArtemis!C23884A8B9E0
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
CylanceUnsafe
PandaTrj/CI.A
ZonerTrojan.Win32.46437
ESET-NOD32a variant of Win32/LockScreen.AGU
TencentWin32.Trojan.Blocker.Svgy
YandexTrojan.WinBlock.Black.Gen.AA
IkarusTrojan-Ransom.Win32.Birele
FortinetW32/LockScreen.AGU!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.8b9e0e
AvastWin32:Evo-gen [Susp]
CrowdStrikemalicious_confidence_80% (W)
Qihoo-360HEUR/QVM41.2.4923.Malware.Gen

How to remove Mal/Ransom-AI?

Mal/Ransom-AI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment