Ransom

About “MSIL:Ransom-AV [Trj]” infection

Malware Removal

The MSIL:Ransom-AV [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Ransom-AV [Trj] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL:Ransom-AV [Trj]?


File Info:

crc32: 863D2E80
md5: 4435d723aa710453c88d7b70b450fb0c
name: 4435D723AA710453C88D7B70B450FB0C.mlw
sha1: ac4169619624ba7ade6d5685e7e8b15b8fbce138
sha256: c63b68f8d939d1bb09f4be6264bf8f6ef60e98cd932401dabcf901a9830078f1
sha512: 1bb7b520e25ff46d721dbf092c0631ebcaeaaa0e0a311e868ad4b9728357c411e5e3ebfba9011ab9bf802c4b0fa8d6ceb786f4ab30707813b354805e9090fb68
ssdeep: 6144:mp77P8eRz2paS+u6ebygnoopPC5BS/T9:mR0AzgnoopPC5BS/p
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: systemkill.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: systemkill.exe

MSIL:Ransom-AV [Trj] also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.19624b
SymantecTrojan Horse
APEXMalicious
AvastMSIL:Ransom-AV [Trj]
KasperskyHEUR:Trojan.MSIL.Fsysna.gen
NANO-AntivirusTrojan.Win32.Ransom.embwxw
TencentMsil.Trojan.Msilperseus.Palp
SophosMal/Generic-S
ComodoMalware@#3v6e58c811mkt
BitDefenderThetaGen:NN.ZemsilF.34058.om0@a4ebadh
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.4435d723aa710453
SentinelOneStatic AI – Malicious PE
AviraTR/Ransom.cgkxz
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.243C782
MicrosoftBackdoor:Win32/Bladabindi!ml
McAfeeArtemis!4435D723AA71
MAXmalware (ai score=100)
PandaTrj/GdSda.A
YandexTrojan.Agent!4wcZzy/49uA
MaxSecureTrojan.Malware.300983.susgen
FortinetGenerik.OERHAZ!tr
AVGMSIL:Ransom-AV [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwMA2NUA

How to remove MSIL:Ransom-AV [Trj]?

MSIL:Ransom-AV [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment