Ransom

MBR:Ransom-C [Trj] removal

Malware Removal

The MBR:Ransom-C [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MBR:Ransom-C [Trj] virus can do?

  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MBR:Ransom-C [Trj]?


File Info:

crc32: CE79C60D
md5: e9fdc21bd273444925a4512166188e5b
name: tunamor.exe
sha1: e398138686eedcd8ef9de5342025f7118e120cdf
sha256: 78972cdde1a038f249b481ea2c4b172cc258aa294440333e9c46dcb3fbed5815
sha512: 64989534f56fcd70f3ff08bb47a331d5624fc1e3b387420a885d6f32a537e05182de8c5890612cde03fdd312ad101955674d7455c84b900bf7eed97b402a2b08
ssdeep: 768:Uv3mq1oJQpwvZlXhVkcDsaoi9P9TJKvaoStYARRQwfwiIySf4BtIl82+hE8x:YmqMQoXhVN4aooJhDCSeyxel82WNx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MBR:Ransom-C [Trj] also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.RTH.1
McAfeeGenericR-QIP!E9FDC21BD273
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Petr.tquH
SangforMalware
K7AntiVirusTrojan ( 004e1c831 )
BitDefenderGen:Heur.Ransom.RTH.1
K7GWTrojan ( 004e1c831 )
CrowdStrikewin/malicious_confidence_80% (W)
CyrenW32/Injector.PEQY-5235
SymantecRansom.Petya
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Petya-6992434-0
KasperskyTrojan-Ransom.Win32.Petr.aqv
AlibabaRansom:Win32/Mbrint.181211
NANO-AntivirusTrojan.Win32.Diskcoder.fhbqwx
SUPERAntiSpywareTrojan.Agent/Gen-DiskCoder
RisingRansom.MBBlocker!8.31B7 (TFE:3:wH9EH9K81xH)
Ad-AwareGen:Heur.Ransom.RTH.1
TACHYONTrojan/W32.DP-DiskWriter.73216
EmsisoftGen:Heur.Ransom.RTH.1 (B)
ComodoMalware@#5d6gj25p7ak9
F-SecureHeuristic.HEUR/AGEN.1117117
DrWebTrojan.Siggen7.57150
ZillyaTrojan.Petr.Win32.114
InvinceaMal/Generic-S
McAfee-GW-EditionGenericR-QIP!E9FDC21BD273
FireEyeGeneric.mg.e9fdc21bd2734449
SophosMal/Generic-S
JiangminAdWare.Generic.svgg
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1117117
Antiy-AVLTrojan/Win32.DiskWriter
MicrosoftRansom:Win32/Petya.A
ArcabitTrojan.Ransom.RTH.1
ZoneAlarmTrojan-Ransom.Win32.Petr.aqv
GDataGen:Heur.Ransom.RTH.1
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2672345
VBA32TScope.Trojan.Delf
ALYacGen:Heur.Ransom.RTH.1
MAXmalware (ai score=81)
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32Win32/Diskcoder.Petya.A
TencentMalware.Win32.Gencirc.10b9a637
YandexTrojan.Agent!k6GxQdsZptA
IkarusTrojan.Win32.Diskcoder
FortinetW32/Petya.A!tr.ransom
BitDefenderThetaAI:Packer.FD0CED3F19
AVGMBR:Ransom-C [Trj]
Cybereasonmalicious.bd2734
AvastMBR:Ransom-C [Trj]
Qihoo-360Win32/Trojan.Ransom.261

How to remove MBR:Ransom-C [Trj]?

MBR:Ransom-C [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment