Ransom

Ransom.1646 information

Malware Removal

The Ransom.1646 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.1646 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Bolivia)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.1646?


File Info:

crc32: E59C1EDE
md5: e63dd859c79f1499a68202456e1b38d7
name: E63DD859C79F1499A68202456E1B38D7.mlw
sha1: c16bbc5336ad978f711b49ae4f72269a9731c7e5
sha256: 0cebe310241dcd1fc41b34a935f5b7a2fe0f443e540a9d2ccd04cb44d2fe2152
sha512: 22c16861ead82726595b065954b3415fd54c5642a387f09faf0a811364dc0ae5ab71e87e520f462599239d0cf67991d26b0e316b847db061cad86014b4fab7f1
ssdeep: 6144:wPTu7Twl77rbe/wAXMOA8x6F2eSsNkjRsY:wLu7TkG/9MOA1/kj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom.1646 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0054b8501 )
LionicTrojan.Win32.Crypmod.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.27814
MicroWorld-eScanGen:Variant.Ransom.1646
ALYacGen:Variant.Ransom.1646
CylanceUnsafe
ZillyaTrojan.Crypmod.Win32.1187
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0054b8501 )
Cybereasonmalicious.9c79f1
CyrenW32/S-c52b1bf2!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GRVY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crypmod.accb
BitDefenderGen:Variant.Ransom.1646
NANO-AntivirusTrojan.Win32.Crypmod.foyzrl
TencentWin32.Trojan.Crypmod.Airt
Ad-AwareGen:Variant.Ransom.1646
SophosML/PE-A + Mal/Qbot-X
ComodoMalware@#1mczv542qt7a6
BitDefenderThetaAI:Packer.964A88521F
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.e63dd859c79f1499
EmsisoftGen:Variant.Ransom.GandCrab.2147 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Tepfer.jhr
AviraTR/Crypt.ULPM.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.2B1FBCD
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Ransom.GandCrab.D863
GDataGen:Variant.Ransom.1646
AhnLab-V3Trojan/Win32.MalPe.R265570
Acronissuspicious
McAfeeArtemis!E63DD859C79F
MAXmalware (ai score=100)
VBA32BScope.Trojan.AntiAV
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74239839.susgen
FortinetW32/Kryptik.GRUH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Crypmod.HwsB5PcA

How to remove Ransom.1646?

Ransom.1646 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment