Ransom

Ransom.1131 information

Malware Removal

The Ransom.1131 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.1131 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Detects the presence of Wine emulator via function name
  • Detects Sandboxie through the presence of a library
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.1131?


File Info:

crc32: F4CDD8DD
md5: a64d3a0a305f2c650f57d05e591dfe15
name: A64D3A0A305F2C650F57D05E591DFE15.mlw
sha1: ff81f09504ad5a5af8b93c68b742277c1107b075
sha256: b1892e40a2f4c8a56e7e7b5a50c57162700c7e28b508aa046305ea4f96896f6e
sha512: 335654028e91838ec192a889dbbbb9ae6f9098c022c36d1c5e74b657db60cca45c163b2ae15e251145d048c5adf265dafa97063dcb27807c0d1ffe41fbb88544
ssdeep: 768:3lLNrj0GqAFPeoTcVkFK1tIQRUw03nkw1z+El3ps/n9Bgp9QcrgKuJUw:1yGqN1kFwfRVInkg9WvEWcrgKuJB
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: yeet.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: yeet.exe

Ransom.1131 also known as:

K7AntiVirusTrojan ( 004b4ab01 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.1131
CylanceUnsafe
ZillyaDropper.Gen.Win32.5385
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004b4ab01 )
Cybereasonmalicious.a305f2
CyrenW32/S-b748adc5!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.RZS
APEXMalicious
AvastMSIL:GenMalicious-BIU [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.1131
NANO-AntivirusTrojan.Win32.Confuser.ezpeci
MicroWorld-eScanGen:Variant.Ransom.1131
TencentWin32.Trojan.Generic.Llhd
Ad-AwareGen:Variant.Ransom.1131
SophosGeneric PUA PP (PUA)
ComodoMalware@#159go98z5n2eb
BitDefenderThetaGen:NN.ZemsilF.34770.cm0@a4PvVBf
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
FireEyeGeneric.mg.a64d3a0a305f2c65
EmsisoftGen:Variant.Ransom.1131 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cbyyi
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Ransom.D46B
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.1131
McAfeeArtemis!A64D3A0A305F
MAXmalware (ai score=98)
MalwarebytesMalware.AI.1365940961
PandaTrj/GdSda.A
YandexTrojan.Agent!X1Cm82bOeR8
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGMSIL:GenMalicious-BIU [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HwMAEpsA

How to remove Ransom.1131?

Ransom.1131 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment