Ransom

Ransom.916 malicious file

Malware Removal

The Ransom.916 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.916 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes

Related domains:

collegefan.collegefan.org

How to determine Ransom.916?


File Info:

crc32: 18FD61DD
md5: 227b29acc48d064d55f2de6f922722e0
name: 227B29ACC48D064D55F2DE6F922722E0.mlw
sha1: 34a7d393bd442f8a5dcd21c38ab6a3effb4cb548
sha256: 388b4da558f59e668cf0e955f936cb4eb44877f04627636bced5bb1ec08c63f0
sha512: 901d9becf934aef8f9df2f90f69415400197fd1645a3087fc6aff4b6bc1de2dc8bde093cce9718e7a6ccc0923efb995262da38a979bd75eaea1f9240f981e450
ssdeep: 1536:FzqMFdn5f2x0E6f0E/l/koLH2N8TZzcjoH3c3LhlO:Fz5FdFE20E/lcorYY3c7y
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018 xc2xa91999-2015 Jonathan Bennett & AutoIt Team
Assembly Version: 1.0.0.0
InternalName: WMM2CLIP.exe
FileVersion: 1.0.0.0
CompanyName: xc2xa91999-2015 Jonathan Bennett & AutoIt Team
LegalTrademarks: xc2xa91999-2015 Jonathan Bennett & AutoIt Team
Comments: xc2xa91999-2015 Jonathan Bennett & AutoIt Team
ProductName: xc2xa91999-2015 Jonathan Bennett & AutoIt Team
ProductVersion: 1.0.0.0
FileDescription: xc2xa91999-2015 Jonathan Bennett & AutoIt Team
OriginalFilename: WMM2CLIP.exe

Ransom.916 also known as:

LionicTrojan.MSIL.Blocker.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader19.37002
ALYacGen:Variant.Ransom.916
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.40414
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:MSIL/GenKryptik.f9305d97
K7GWTrojan ( 0052f20d1 )
K7AntiVirusTrojan ( 0052f20d1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/GenKryptik.BXYX
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderGen:Variant.Ransom.916
NANO-AntivirusTrojan.Win32.Ransom.fibdps
MicroWorld-eScanGen:Variant.Ransom.916
TencentMsil.Trojan.Blocker.Hpih
Ad-AwareGen:Variant.Ransom.916
SophosMal/Generic-S
ComodoMalware@#l48aqu6yk4lk
McAfee-GW-EditionPacked-FGX!227B29ACC48D
FireEyeGeneric.mg.227b29acc48d064d
EmsisoftGen:Variant.Ransom.916 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.keab
AviraHEUR/AGEN.1126764
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2816B2F
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Ransom.916
GDataGen:Variant.Ransom.916
McAfeePacked-FGX!227B29ACC48D
MAXmalware (ai score=99)
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.CELB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOUA

How to remove Ransom.916?

Ransom.916 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment