Ransom

About “MSIL:Ransom-BB [Trj]” infection

Malware Removal

The MSIL:Ransom-BB [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Ransom-BB [Trj] virus can do?

    How to determine MSIL:Ransom-BB [Trj]?

    
    

    File Info:

    crc32: A2324580
    md5: 6f6c476bd90b09b81a099cad8f89f5aa
    name: 6F6C476BD90B09B81A099CAD8F89F5AA.mlw
    sha1: 2bd89875730906096ccd7f507e4aa53d224c3bec
    sha256: 7057bfe569ecd727bf8ebc07bca51d6bc3605522b6eed6709f3792e93a40f00e
    sha512: 8338b98fc1204d9964ad0520f94d670e51bd5ba5ad3eee5353bb64ae7cbc73ba98b913cec7ecd4d3bfdff2c7daa8f478018c449b7cd22cea9fe2963331c5970f
    ssdeep: 6144:gluRfH7/ODQtKD5Z2NVzmC3tQY4dLUqKD5Z5I:w4k5Yj33tZ4Pk54
    type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

    Version Info:

    Translation: 0x0000 0x04b0
    LegalCopyright:
    Assembly Version: 1.0.0.0
    InternalName: Runsome.exe
    FileVersion: 1.0.0.0
    ProductName: Cyber SpliTTer Vbs
    ProductVersion: 1.0.0.0
    FileDescription: Cyber SpliTTer Vbs
    OriginalFilename: Runsome.exe

    MSIL:Ransom-BB [Trj] also known as:

    DrWebTrojan.DownLoader11.25560
    CynetMalicious (score: 85)
    ALYacTrojan.Ransom.CyberSplitter
    CylanceUnsafe
    ZillyaTrojan.Crypmodadv.Win32.107
    SangforRansom.Win32.BlueEagle.3
    CrowdStrikewin/malicious_confidence_80% (W)
    AlibabaRansom:Win32/Crypmodadv.4acfd3d4
    K7GWTrojan ( 004de29f1 )
    K7AntiVirusTrojan ( 004de29f1 )
    SymantecTrojan.Bleagle
    ESET-NOD32a variant of MSIL/Filecoder.AK
    APEXMalicious
    AvastMSIL:Ransom-BB [Trj]
    KasperskyTrojan-Ransom.Win32.Crypmodadv.xez
    BitDefenderGen:Variant.Ransom.BlueEagle.3
    NANO-AntivirusTrojan.Win32.Crypmodadv.elnvcn
    MicroWorld-eScanGen:Variant.Ransom.BlueEagle.3
    TencentWin32.Trojan.Win32.Trojan.Filecoder.cryp.clbc
    Ad-AwareGen:Variant.Ransom.BlueEagle.3
    SophosMal/Generic-R + Mal/Cryptear-A
    ComodoMalware@#2usr4vp8rn77a
    BitDefenderThetaGen:NN.ZemsilF.34670.5q0@aChpJLm
    TrendMicroRansom_EDA2Runsome.G
    McAfee-GW-EditionRDN/Ransom.bz
    FireEyeGeneric.mg.6f6c476bd90b09b8
    EmsisoftTrojan.FileCoder (A)
    SentinelOneStatic AI – Malicious PE
    WebrootW32.Crypmodadv
    AviraTR/FileCoder.nzaml
    eGambitUnsafe.AI_Score_99%
    KingsoftWin32.Troj.Undef.(kcloud)
    MicrosoftRansom:Win32/FileCryptor
    ArcabitTrojan.Ransom.BlueEagle.3
    AegisLabTrojan.Win32.Crypmodadv.j!c
    GDataMSIL.Trojan-Ransom.CyberSplitter.A
    AhnLab-V3Trojan/Win32.FileCoder.C1784681
    McAfeeRDN/Ransom.bz
    MAXmalware (ai score=100)
    VBA32Hoax.Crypmodadv
    MalwarebytesMalware.AI.4023067198
    PandaTrj/GdSda.A
    TrendMicro-HouseCallRansom_EDA2Runsome.G
    YandexTrojan.Crypmodadv!lxG+IspBCdQ
    IkarusTrojan-Ransom.CyberSplitter
    FortinetMSIL/Filecoder.AK!tr.ransom
    AVGMSIL:Ransom-BB [Trj]
    Paloaltogeneric.ml
    Qihoo-360Win32/Ransom.Crypmodadv.HwMAKW4A

    How to remove MSIL:Ransom-BB [Trj]?

    MSIL:Ransom-BB [Trj] removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment