Ransom

Ransom.385 information

Malware Removal

The Ransom.385 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.385 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom.385?


File Info:

crc32: 21F77DB2
md5: b9e3ea104d9e75fb56dcbca4dfafe50c
name: B9E3EA104D9E75FB56DCBCA4DFAFE50C.mlw
sha1: 62336465f37c7d0cf9b90fc753a1ffa5b3491dc7
sha256: 54298be1958c955413763340b0e7b3a80ac80d0166b47a62aadbfac790ad89f2
sha512: db307f690497ed73aa541275737bea5e745e8792c24d711522497287b5eb73b1feb4d445eebfa00e0f1135bb858d03d06d7ca09abc26f03c1a6c8a5bf59acf20
ssdeep: 768:OfvdWST3xRbyApqHuDlOHTjXhDnyokke5MfED1ns7csFO/7v:CvdWSVRVDlOzjRzrkRAODv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.385 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.385
FireEyeGeneric.mg.b9e3ea104d9e75fb
ALYacGen:Variant.Ransom.385
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Binder.lo77
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004babd11 )
BitDefenderGen:Variant.Ransom.385
K7GWTrojan ( 004babd11 )
Cybereasonmalicious.04d9e7
BaiduWin32.Trojan-Dropper.Binder.m
CyrenW32/Backdoor.FVDJ-1096
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Tool.Binder-9794371-0
KasperskyHackTool.Win32.Binder.bs
AlibabaTrojan:Win32/BlueArmy.2d2
ViRobotTrojan.Win32.A.Swisyn.49120
RisingDropper.Binder!1.AEB1 (CLOUD)
Ad-AwareGen:Variant.Ransom.385
EmsisoftGen:Variant.Ransom.385 (B)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
DrWebTrojan.MulDrop2.39589
ZillyaTool.Binder.Win32.9413
McAfee-GW-EditionBehavesLike.Win32.PUP.lt
SophosMal/Vbinder-D
IkarusTrojan.Win32.Dorv
JiangminHackTool.Binder.bh
MAXmalware (ai score=85)
KingsoftWin32.Binder.bs.(kcloud)
MicrosoftVirTool:Win32/Vbinder.CO
ArcabitTrojan.Ransom.385
ZoneAlarmHackTool.Win32.Binder.bs
GDataGen:Variant.Ransom.385
CynetMalicious (score: 100)
McAfeeArtemis!B9E3EA104D9E
TACHYONTrojan/W32.Binder.73728
MalwarebytesDarkComet.Backdoor.RAT.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/TrojanDropper.Binder.NBH
TencentWin32.Hacktool.Binder.Pjdj
YandexTrojan.GenAsa!o/ixl7L2Afs
SentinelOneStatic AI – Suspicious PE
eGambitTrojan.Generic
FortinetW32/Dropper.NBH!tr
BitDefenderThetaGen:NN.ZexaF.34590.euW@ae3UkWdO
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/HackTool.Binder.HgIASOcA

How to remove Ransom.385?

Ransom.385 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment