Ransom

Ransom.1994 malicious file

Malware Removal

The Ransom.1994 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.1994 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable UAC

Related domains:

z.whorecord.xyz
www.filmgetir.com
ww1.filmgetir.com
a.tomx.xyz
www.filmver.com
www.pornokan.com

How to determine Ransom.1994?


File Info:

crc32: A36433CE
md5: 56acd55efebc63546d87c94970c6304b
name: 56ACD55EFEBC63546D87C94970C6304B.mlw
sha1: 8ba352d9986848e3755caac6b02681e7d5c069c3
sha256: 428edc14c12bb5c3b2da0e10115d8d0e15236adc57c3f3c9211d3bc40815446e
sha512: 269a40e376c711784e05efd919b164622dc24ab3b6497b9a72c1414164125fece6d51ef5d046609704d4de10c86a5f2f4260ec8a4554e8d7ced56f4c9a7ef7c1
ssdeep: 12288:6NIQAPGsAqY9IMVYd38sJdpQHitlY8Kf8fw6qQxNtI:nPGSY91VwNJcCTq87rI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Apple Inc.
FileDescription: Apple Inc. 9.1.2 Installation
FileVersion: 9.1.2
Comments:
CompanyName: Apple Inc.
Translation: 0x0409 0x04e4

Ransom.1994 also known as:

K7AntiVirusTrojan ( 004c2c031 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader13.16321
CynetMalicious (score: 99)
CAT-QuickHealTrojanRansom.Blocker
ALYacGen:Variant.Ransom.1994
CylanceUnsafe
SangforRansom.Win32.Blocker.kwrv
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Blocker.d0fa50eb
K7GWTrojan ( 004c2c031 )
Cybereasonmalicious.efebc6
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/ExtenBro.BE
APEXMalicious
AvastWin32:Downloader-VYF [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.kwrv
BitDefenderGen:Variant.Ransom.1994
NANO-AntivirusTrojan.Win32.Dwn.dsxnlt
ViRobotTrojan.Win32.S.Agent.678375
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanGen:Variant.Ransom.1994
TencentMalware.Win32.Gencirc.114d5652
Ad-AwareGen:Variant.Ransom.1994
SophosMal/Generic-S
ComodoMalware@#3f6d4zoux9jzo
BitDefenderThetaGen:NN.ZexaF.34690.Pq3@a8HZaqli
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BPUSH.SM
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.56acd55efebc6354
EmsisoftGen:Variant.Ransom.1994 (B)
JiangminTrojan/Generic.befhx
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1106598
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Kilim.U
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ransom.1994
AhnLab-V3Trojan/Win32.Blocker.C742060
McAfeeArtemis!56ACD55EFEBC
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesTrojan.KBayi.FLA
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BPUSH.SM
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Agent!w+KF7mHh99E
IkarusTrojan.Win32.AHK
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic!tr
AVGWin32:Downloader-VYF [Trj]
Paloaltogeneric.ml

How to remove Ransom.1994?

Ransom.1994 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment