Ransom

Ransom.948 (file analysis)

Malware Removal

The Ransom.948 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.948 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ransom.948?


File Info:

crc32: 68FA1C99
md5: bea1453afaf3afdd3d035142cc9ce4c9
name: BEA1453AFAF3AFDD3D035142CC9CE4C9.mlw
sha1: 60a04f36b67251eb50b8134b84336ecb3346e017
sha256: 523262b6935b3dfc8a26ff9f15340cb0fc536c452f3e9492bed4bb4f680ddfd2
sha512: eb7b655e5b83780260d1f14402b1cd2d1d65cc6ce5218e4f0fb59b7e0ec344bfcc14555139e9b7411d65ed0ea93287ffe0ebca179ad12b48c7292ba7f84cd401
ssdeep: 96:RSkdIBTp7rFabSoEOX28jDcR2dhy2eqsZirzNt:PdWp4EpcQRiRjt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: WindowsApplication.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: WindowsApplication.exe

Ransom.948 also known as:

K7AntiVirusTrojan ( 005245171 )
DrWebTrojan.PWS.Stealer.24980
CynetMalicious (score: 90)
ALYacGen:Variant.Ransom.948
CylanceUnsafe
ZillyaTrojan.Generic.Win32.141521
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Malex.8dddad48
K7GWTrojan ( 005245171 )
Cybereasonmalicious.afaf3a
CyrenW32/MSIL_Troj.RZ.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of MSIL/ClipBanker.CB
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Ransom.948
NANO-AntivirusTrojan.Win32.Blocker.exfywe
MicroWorld-eScanGen:Variant.Ransom.948
TencentWin32.Trojan.Generic.Pjnd
Ad-AwareGen:Variant.Ransom.948
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34628.am0@aGZeYbl
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.cyg
FireEyeGeneric.mg.bea1453afaf3afdd
EmsisoftGen:Variant.Ransom.948 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.ClipBanker.sarli
MicrosoftTrojan:Win32/Malex.gen!F
ArcabitTrojan.Ransom.948
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Variant.Ransom.948
AhnLab-V3Trojan/Win32.RL_Generic.C3975825
McAfeeGeneric.cyg
MAXmalware (ai score=98)
VBA32Trojan-Ransom.Blocker
MalwarebytesBackdoor.Agent
PandaTrj/GdSda.A
RisingRansom.Generic!8.E315 (CLOUD)
YandexTrojan.Blocker!pm34SxDnMRc
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/ClipBanker.CB!tr
AVGWin32:Malware-gen
Qihoo-360Win32/HackTool.Malex.HgIASREA

How to remove Ransom.948?

Ransom.948 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment