Ransom

How to remove “Ransom.10”?

Malware Removal

The Ransom.10 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.10 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom.10?


File Info:

crc32: E28747F3
md5: e1e3dfa48a1c431aa2167a9bdf586f00
name: E1E3DFA48A1C431AA2167A9BDF586F00.mlw
sha1: 2b2477b99498f1ad41c8f9bef0f014a0042d0d05
sha256: 1e01c8e4b81c1aa345b12543f032eb64540bfc4f8f6109ef8f334c9c59e6f511
sha512: c3e3260bf371bb8f4070b42c20400814d2e204cf1474672cf83d98d0d8a3e1adc279b2597207f05730ea030101d63b90da087679cfa1e4b7ceb137bf4a907db2
ssdeep: 384:lUkP1kSf0S3yc2+DFfRI7xbiNb4A2lO26QbM34OC3L3PpQ0lcCgsQImnI/QAnIZ:lR1kRSCsfRlNM4Qw3U3Ly+cCgHIYAI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2011 Heaventools Software
InternalName: Gsn.exe
FileVersion: 3.0.79.4
CompanyName: BitDefender
ProductName: Gusno
ProductVersion: 3.0.79.4
FileDescription: Gan
OriginalFilename: Gusn.exe
Translation: 0x004b 0x04b0

Ransom.10 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.3445
MicroWorld-eScanGen:Variant.Ransom.10
FireEyeGeneric.mg.e1e3dfa48a1c431a
ALYacGen:Variant.Ransom.10
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 00274f891 )
BitDefenderGen:Variant.Ransom.10
K7GWTrojan ( 00274f891 )
Cybereasonmalicious.48a1c4
BitDefenderThetaGen:NN.ZexaF.34590.bu0@aq21x0nc
CyrenW32/Ransom.O.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_KRYPTK.SM21
AvastWin32:Malware-gen
ClamAVWin.Trojan.Pornoasset-44
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.f9bbf8bd
NANO-AntivirusTrojan.Win32.Winlock.eiavru
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.114b5f6b
Ad-AwareGen:Variant.Ransom.10
EmsisoftGen:Variant.Ransom.10 (B)
ComodoMalware@#32035w7qcgpcg
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroTROJ_KRYPTK.SM21
McAfee-GW-EditionBehavesLike.Win32.Dropper.mm
SophosMal/Generic-S
IkarusTrojan-Ransom.PornoAsset
WebrootW32.Rogue.Pornoasset.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Ymacco.AB1E
ArcabitTrojan.Ransom.10
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.10
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.PornoAsset.R20667
McAfeeArtemis!E1E3DFA48A1C
VBA32BScope.Trojan.Winlock
MalwarebytesSpyware.PasswordStealer.XGen
PandaGeneric Malware
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.ONM
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.PornoAsset!K++GQUJgFXA
SentinelOneStatic AI – Malicious PE
FortinetW32/KRYPTK.SM21!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Generic.HwgARi8A

How to remove Ransom.10?

Ransom.10 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment