Ransom

Ransom.14 malicious file

Malware Removal

The Ransom.14 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.14 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Ransom.14?


File Info:

name: 0739FA4A6BA295232A5B.mlw
path: /opt/CAPEv2/storage/binaries/0d19ae5ac217c1432fce6669a02e2d0ce8f6384e3dade6bfd2ef6c8482e8412d
crc32: 97AC6001
md5: 0739fa4a6ba295232a5b3cd05e5068ea
sha1: d153e8c4d5eeaba92e108b83c2cd60bc1f9023a0
sha256: 0d19ae5ac217c1432fce6669a02e2d0ce8f6384e3dade6bfd2ef6c8482e8412d
sha512: 425148b903bd6a8d70f7e02a331508a1978e1103b90e9f4f7cbe0784dd64678cc55349bfc5720930573e7b5e63a7ae0b15bb87aba5f82529b9b159590d9f3bc1
ssdeep: 384:5BhDLcfIwB1HvjNj5fvmgXQHHD15ERX/GKf9HspnZBRDmH:6wuXV33cHh5ERN9iZLDm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9B2CF13BBE1505BE09923308567C30BEAD73C69EA765807BFE24F9E1867002DD17E5A
sha3_384: 8aed4f6887e5d72e7bde7e2bd0a8960417f27342426ac771a2874c9c569f1cd580b6d9a97df7dd04a7a90523c4ba44d7
ep_bytes: 6a086838624000e824f5ffff6a00683c
timestamp: 2011-06-25 14:59:38

Version Info:

CompanyName: BitDefender
FileDescription: kIseu
FileVersion: 6.2.7.0
InternalName: Lusmpwi.exe
LegalCopyright: (c) ZZZX
OriginalFilename: Dwoeie.exe
ProductName: peuselipess
ProductVersion: 6.2.7.0
Translation: 0x086b 0x04b0

Ransom.14 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Winlock.3445
MicroWorld-eScanGen:Variant.Ransom.14
FireEyeGeneric.mg.0739fa4a6ba29523
McAfeeArtemis!0739FA4A6BA2
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.208632
SangforTrojan.Win32.Vigorf.A
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Kryptik.66b6ee18
K7GWRiskware ( 0015e4f01 )
K7AntiVirusRiskware ( 0015e4f01 )
BitDefenderThetaGen:NN.ZexaF.34698.bu0@aatnIOmc
VirITTrojan.Win32.Generic.FYN
CyrenW32/Ransom.O.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.PPO
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.14
NANO-AntivirusTrojan.Win32.Winlock.kenmk
SUPERAntiSpywareTrojan.Agent/Gen-Falint
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Cdhl
Ad-AwareGen:Variant.Ransom.14
EmsisoftGen:Variant.Ransom.14 (B)
ComodoMalware@#21vm9mpcur8l6
VIPREGen:Variant.Ransom.14
TrendMicroTROJ_RANSOM.GER
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/FakeAV-NI
IkarusTrojan-Ransom.PornoAsset
GDataGen:Variant.Ransom.14
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1219280
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Vigorf.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransomlock.R7639
Acronissuspicious
VBA32BScope.Trojan.FakeAlert
ALYacGen:Variant.Ransom.14
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_RANSOM.GER
RisingRansom.Genasom!8.293 (TFE:2:B8O9kk317FK)
YandexTrojan.GenAsa!uO97ORy7fOE
SentinelOneStatic AI – Suspicious PE
FortinetW32/Zbot.CU!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.a6ba29
PandaTrj/Genetic.gen

How to remove Ransom.14?

Ransom.14 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment