Ransom

Ransom.Agent.RRE removal tips

Malware Removal

The Ransom.Agent.RRE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Agent.RRE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Ransom.Agent.RRE?


File Info:

crc32: 14C26E76
md5: 9f34ef5374bc3b8eecab0caef3eb1f70
name: 9F34EF5374BC3B8EECAB0CAEF3EB1F70.mlw
sha1: 5f884b1978b52bc9e66b3ef8ad8f92ced7c9bb64
sha256: 584bb5f736f949f5da1e42413566bf95ee60fa738f2dc8d07a4713fd999ed85b
sha512: 690f934a9f6e03ec12aee3c2a4f9cfc8a5ce72661363eb52019ccda6e300db7d6bfce107e2e9eba792366a7f271c4ed76014732df3f55dd82c359477e3047722
ssdeep: 3072:go8FkcP4veQOxO9c/bWK43LYEkfS6LfY9Igi8D:h+A9Y279gwi0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Agent.RRE also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Winlock.8128
CynetMalicious (score: 100)
CAT-QuickHealRansom.Urausy.C5
ALYacGen:Variant.Symmi.19517
CylanceUnsafe
ZillyaTrojan.Injector.Win32.407168
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Urausy.70c7cf67
K7GWTrojan ( 0040f3c81 )
K7AntiVirusTrojan ( 0040f3c81 )
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Divi.B.gen!Eldorado
ESET-NOD32Win32/LockScreen.APR
APEXMalicious
AvastWin32:LockScreen-XC [Trj]
ClamAVWin.Ransomware.Urausy-9760831-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.19517
NANO-AntivirusTrojan.Win32.Winlock.cqovsz
SUPERAntiSpywareTrojan.Agent/Gen-Renos
MicroWorld-eScanGen:Variant.Symmi.19517
TencentWin32.Trojan.Lockscreen.Hviy
Ad-AwareGen:Variant.Symmi.19517
SophosML/PE-A + Troj/Ransom-TK
ComodoTrojWare.Win32.Ransom.Foreign.SEA@4xzjgq
BitDefenderThetaAI:Packer.F1EACC2521
VIPRETrojan.Win32.FakeAV.ka (v)
TrendMicroTROJ_RANCRYP.SML
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.9f34ef5374bc3b8e
EmsisoftGen:Variant.Symmi.19517 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Foreign.esr
WebrootW32.Rogue.Gen
AviraTR/Kryptik.1146888
eGambitGeneric.Malware
KingsoftWin32.Troj.LockScreen.A.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.AFQ
ArcabitTrojan.Symmi.D4C3D
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.19517
AhnLab-V3Win-Trojan/Yakes.114688
Acronissuspicious
McAfeeRansom-FBUK!9F34EF5374BC
MAXmalware (ai score=100)
VBA32BScope.Trojan.FakeAlert
MalwarebytesRansom.Agent.RRE
PandaTrj/Resdec.HEU
TrendMicro-HouseCallTROJ_RANCRYP.SML
RisingRansom.Urausy!8.2B7 (CLOUD)
YandexTrojan.GenAsa!RGGEE+fOMrU
IkarusTrojan.Win32.FakeAV
FortinetW32/FakeAV.SE!tr
AVGWin32:LockScreen-XC [Trj]
Qihoo-360Win32/Ransom.Urausy.HwgAEpsA

How to remove Ransom.Agent.RRE?

Ransom.Agent.RRE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment