Ransom

Ransom.2019 removal guide

Malware Removal

The Ransom.2019 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.2019 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Reads data out of its own binary image
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

inagxlir.work
xpnyvwwav.work
wvvgxwbiqq.work
jjpiqbiun.su
puuhdrmvwtqc.biz
suyxeyydjexau.su
gpngssocpiqo.org
belrtmr.su

How to determine Ransom.2019?


File Info:

crc32: B0AD7C6A
md5: 6a3a127a25cbcb4e3427f44db95b43d5
name: 6A3A127A25CBCB4E3427F44DB95B43D5.mlw
sha1: 84ca7b99ff4dabb6f0258d4412ed8999a13e0f61
sha256: 4ee737060cc04636a73e770a5548b6cd812132612a1badacfabc62017c6738ee
sha512: 255a60619d0e4011a0d71f1e677b0a3ac9649201f655a7e32430ef77522b4ba8fa44ffd0bda0ab68e781b04a8df288fd6783e0ef7c7cf2a5668fe7b3d9d315bf
ssdeep: 3072:0dxNE+Hb+eyz9zIPqFbvHp/fUfEZBKBzLtS9JcXaP9Gpq+x+l1dg8aW1Cfrfloi9:0W+7+eMnFbSAKBtSJIxMElW1CfrfGW
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: (C) 2016 Oracle
InternalName: VBoxWindowsAdditions-x86.exe
FileVersion: VBox 5.0.1.0
CompanyName: Oracle
ProductName: VBox Guest Additions
ProductVersion: 5.0.1.0
FileDescription: VBox Guest Additions
Translation: 0x040c 0x04e4

Ransom.2019 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Ransom.2019
FireEyeGen:Variant.Ransom.2019
Qihoo-360Win32/Trojan.Generic.HyoD7DsA
ALYacGen:Variant.Ransom.2019
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Ransom.2019
K7GWTrojan ( 004fb47d1 )
K7AntiVirusTrojan ( 004fb47d1 )
SymantecPacked.NSISPacker!g3
ESET-NOD32Win32/Filecoder.Locky.C
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Locky.9db12ec6
NANO-AntivirusTrojan.Win32.Encoder.eifdff
Ad-AwareGen:Variant.Ransom.2019
SophosMal/Generic-S
ComodoApplicUnwnt@#25kc0zs743d5e
F-SecureHeuristic.HEUR/AGEN.1102533
DrWebTrojan.Encoder.3976
ZillyaTrojan.Locky.Win32.1547
TrendMicroRansom_LOCKY.DLDSAPX
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
EmsisoftGen:Variant.Ransom.2019 (B)
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1102533
MAXmalware (ai score=100)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Locky
ArcabitTrojan.Ransom.D7E3
SUPERAntiSpywareRansom.Locky/Variant
AhnLab-V3Trojan/Win32.Locky.C1614510
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.2019
CynetMalicious (score: 100)
McAfeeArtemis!6A3A127A25CB
VBA32Trojan.Encoder
MalwarebytesRansom.Cerber
PandaTrj/CI.A
TrendMicro-HouseCallRansom_LOCKY.DLDSAPX
TencentWin32.Trojan.Inject.Auto
FortinetW32/Injector.HF!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.a25cbc
Paloaltogeneric.ml

How to remove Ransom.2019?

Ransom.2019 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment