Ransom

Ransom.BitPaymer.18 (file analysis)

Malware Removal

The Ransom.BitPaymer.18 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.BitPaymer.18 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Vietnamese
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom.BitPaymer.18?


File Info:

crc32: 9A6F8A7F
md5: dbde66ab1d4965a6f8970d4b999c8c4c
name: DBDE66AB1D4965A6F8970D4B999C8C4C.mlw
sha1: ae1624fdfda08cad35becd05c0ed21c374a8ee6e
sha256: 897c49f9ddefb34d959ad1e25279cb2ec0fedcc8d914727d08cb7de03363ab5e
sha512: 090e5fb912a9d4eebe422fe175173bcc391540ab353237fa7c9ba4f54ed85d74fba2454d378d0122cbcfe4e8f23708f6a3c7b5eea067cc1f28954455025ce7ac
ssdeep: 3072:3sAhr3aYx1MG7jQN+8h70sLVGGtSrO1ujYg5p6HkwYCMJ5d+l+U7Rg:3jwUeNlos5CO1ujD5/3JXq7y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.BitPaymer.18 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24300
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacGen:Variant.Ransom.BitPaymer.18
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.138069
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.e06fad99
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.b1d496
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJMJ
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.BitPaymer.18
NANO-AntivirusTrojan.Win32.Kryptik.fgfwxk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Variant.Ransom.BitPaymer.18
TencentWin32.Trojan.Generic.Wvkw
Ad-AwareGen:Variant.Ransom.BitPaymer.18
SophosMal/Generic-R + Mal/GandCrab-G
ComodoApplication.Win32.Dlhelper.GJ@8137f9
F-SecureHeuristic.HEUR/AGEN.1106539
BitDefenderThetaGen:NN.ZexaF.34670.luW@aeOhLvgG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.RYUK.SMB
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.dbde66ab1d4965a6
EmsisoftGen:Variant.Ransom.BitPaymer.18 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Coins.alj
AviraHEUR/AGEN.1106539
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Fuerboos
MicrosoftTrojan:Win32/RYUK.DSK!MTB
ArcabitTrojan.Ransom.BitPaymer.18
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.BitPaymer.18
AhnLab-V3Win-Trojan/Gandcrab04.Exp
Acronissuspicious
McAfeePacked-FKD!DBDE66AB1D49
MAXmalware (ai score=100)
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.RYUK.SMB
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
YandexTrojan.PWS.Coins!dL6inpg+3cI
IkarusTrojan.Win32.Danabot
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GKTH!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Ryuk.HwoCEpsA

How to remove Ransom.BitPaymer.18?

Ransom.BitPaymer.18 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment