Ransom

Ransom.1201 removal

Malware Removal

The Ransom.1201 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.1201 virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine Ransom.1201?


File Info:

crc32: 0930DAAA
md5: 5c7fb47c979ca093bd7fc1168fb7c227
name: 5C7FB47C979CA093BD7FC1168FB7C227.mlw
sha1: 3d842e30665f2b264ff390daa7b3bb0c454bb4dd
sha256: 88f10782dbad43756b9f95e91a71fb2900098ac3bc0acc5ac3fe52238e14e2e9
sha512: e9dcb9324f0fe38c35632fdd04c8d04c37f986adf2f494caeeac04bf47750e115be64510a0464edb6fa89b17df6be2e358406c9ba601eb5a73cac2b2e5c5f879
ssdeep: 24576:9quFYf1FUP4iBY1XuIbynBfYFHcj1Cj4z+Qtbc:I8PzYVuzCoIABI
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2008-2018 Eohat
Assembly Version: 0.6.6.8
InternalName: MyCandy.exe
FileVersion: 0.6.6.8
CompanyName: Eohat
LegalTrademarks:
ProductName: Sandpeople
ProductVersion: 0.6.6.8
FileDescription: Sandpeople
OriginalFilename: MyCandy.exe

Ransom.1201 also known as:

K7AntiVirusTrojan ( 0054248a1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.1201
CylanceUnsafe
ZillyaTrojan.Crypren.Win32.751
SangforTrojan.Win32.Generic.2
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:MSIL/Injector.24b45c69
K7GWTrojan ( 0054248a1 )
Cybereasonmalicious.c979ca
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.UDL
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Crypren.gen
BitDefenderGen:Variant.Ransom.1201
MicroWorld-eScanGen:Variant.Ransom.1201
TencentMsil.Trojan.Crypren.Sxyt
Ad-AwareGen:Variant.Ransom.1201
SophosMal/Generic-S
ComodoMalware@#3i296ucsyv0nb
BitDefenderThetaGen:NN.ZemsilF.34670.0m0@aK!B39
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.5c7fb47c979ca093
EmsisoftGen:Variant.Ransom.1201 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.kprn
AviraHEUR/AGEN.1120328
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Ransom.1201
AhnLab-V3Trojan/Win32.Ransom.C2840279
Acronissuspicious
McAfeeGenericRXGP-UE!5C7FB47C979C
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.MSIL
PandaTrj/GdSda.A
RisingRansom.Crypren!8.1D6C (CLOUD)
IkarusTrojan.MSIL.Babel
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Crypren!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.Generic.HwMAEpsA

How to remove Ransom.1201?

Ransom.1201 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment