Ransom

Ransom.948 (B) malicious file

Malware Removal

The Ransom.948 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.948 (B) virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.948 (B)?


File Info:

crc32: 4872EB9D
md5: 6b821bad7a6824190b489086f92e193a
name: 6B821BAD7A6824190B489086F92E193A.mlw
sha1: f6220f9cdcb4b4dce0bd0425163e4b299e3fbf2a
sha256: bf272717eb8489676f8da682403ee6b6cdfd352c4bbbe8d15ecb026dd01bc0e3
sha512: 658a9af043e004b8d94ae66534577682cd540a93e80fad4450a8f608cf73c3e8680ef18e4d8d7b3a10ca32f162881b304845f947e43903029203c4e84252b357
ssdeep: 96:sMSkdIBTp7rFabSoEOX28jDcR2dgydv6sZirzNt:sIdWp4EpcQRiRut
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: WindowsApplication.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: WindowsApplication.exe

Ransom.948 (B) also known as:

K7AntiVirusTrojan ( 0050db261 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.PWS.Stealer.24980
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.948
CylanceUnsafe
ZillyaTrojan.Generic.Win32.141521
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Malex.3ebadbcb
K7GWTrojan ( 0050db261 )
Cybereasonmalicious.d7a682
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/ClipBanker.CB
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Ransom.948
NANO-AntivirusTrojan.Win32.ClipBanker.fikkgf
MicroWorld-eScanGen:Variant.Ransom.948
TencentWin32.Trojan.Spy.Wqww
Ad-AwareGen:Variant.Ransom.948
SophosMal/Generic-S
ComodoMalware@#1z94md86ia4y2
BitDefenderThetaGen:NN.ZemsilF.34050.am0@aa8J18m
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareTskLnk.zt
FireEyeGeneric.mg.6b821bad7a682419
EmsisoftGen:Variant.Ransom.948 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cquaz
AviraTR/Spy.ClipBanker.tzrhi
Antiy-AVLTrojan/Generic.ASMalwS.282FB85
MicrosoftTrojan:Win32/Malex.gen!F
ArcabitTrojan.Ransom.948
GDataGen:Variant.Ransom.948
AhnLab-V3Trojan/Win32.RL_Generic.C3975825
McAfeeArtemis!6B821BAD7A68
MAXmalware (ai score=99)
VBA32Trojan.MSIL.gen.11
PandaTrj/GdSda.A
YandexTrojan.ClipBanker!MWEEtfllOWo
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.CB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/HackTool.Malex.HgIASREA

How to remove Ransom.948 (B)?

Ransom.948 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment