Ransom

How to remove “Ransom.1764 (B)”?

Malware Removal

The Ransom.1764 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.1764 (B) virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Ransom.1764 (B)?


File Info:

name: 60BDA893073E8B013816.mlw
path: /opt/CAPEv2/storage/binaries/5e483d66f3abb2130e30e74ebda1505dc01a635e67b8f290ea84d52735750c6d
crc32: 3E31D656
md5: 60bda893073e8b01381608ae805a8753
sha1: 7d84c181bee287ccf847747eb4c00971b578801e
sha256: 5e483d66f3abb2130e30e74ebda1505dc01a635e67b8f290ea84d52735750c6d
sha512: 821e9a0a2c50141e7245b9b7948f8f3830d4ce2df00417504d040fa1b001ab2d7563c7efacf5c41392136571c4cbf6fe7f899b3403d54fe653f54622e27a7d95
ssdeep: 6144:iA9BQA9BcA9BMMatHEQ+sfaYj8rVuKAdB:FBPBjB5atkQ+sfxaVutB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B05D1F09E9208E3D6D68A748FA9B2CCAB4E96B1F5DDE62E149F0147CB31594F4C502C
sha3_384: aabab5328f15fefca9e6a028efe5563bae765eafb749c234d8be58b7b57b3cf5e1294d3b5659681cee4cedf4c01e8dd3
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-02-12 23:26:23

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Calculadora de minería
FileVersion: 1.0.0.0
InternalName: Calculadora de minería.exe
LegalCopyright: Copyright © 2020
OriginalFilename: Calculadora de minería.exe
ProductName: Calculadora de minería
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ransom.1764 (B) also known as:

LionicTrojan.Win32.Malicious.4!c
CynetMalicious (score: 99)
McAfeeArtemis!60BDA893073E
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Ransom.1764
CrowdStrikewin/malicious_confidence_90% (W)
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Ransom.1764
MicroWorld-eScanGen:Variant.Ransom.1764
AvastWin32:Malware-gen
EmsisoftGen:Variant.Ransom.1764 (B)
F-SecureTrojan.TR/Ransom.fnoip
VIPREGen:Variant.Ransom.1764
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Ransom.1764
GDataGen:Variant.Ransom.1764
WebrootW32.Trojan.Gen
AviraTR/Ransom.fnoip
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Ransom.D6E4
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGen:Variant.Ransom.1764
Cylanceunsafe
RisingMalware.Obfus/MSIL@AI.81 (RDM.MSIL2:gxHv9EpUGKrKBizNdoh4QQ)
MaxSecureTrojan.Malware.74837345.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.3073e8
DeepInstinctMALICIOUS

How to remove Ransom.1764 (B)?

Ransom.1764 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment