Ransom

Ransom.BitRansomware removal tips

Malware Removal

The Ransom.BitRansomware is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.BitRansomware virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Ransom.BitRansomware?


File Info:

name: BF02FD4C142D699506EB.mlw
path: /opt/CAPEv2/storage/binaries/e1215cb146734fba6de6b754666bb8e9b5b9c94954f110e1d7ccfb0403c9c803
crc32: B30B87D3
md5: bf02fd4c142d699506ebf779023e1992
sha1: 231cce575fa026b337b103deec38bb0cf8be874b
sha256: e1215cb146734fba6de6b754666bb8e9b5b9c94954f110e1d7ccfb0403c9c803
sha512: df22da2a87e165269779f083ad12c9a5100fbb665e94d88cd37b713d8cad85e35ae98ce637768258d78ffd098d23e3ef205cf603c17f3cdd3eefc3819a42fb72
ssdeep: 1536:8avojrBUg04yROxzERqI8ZhWo78whRVEQ8lMbXwmHgRa95RbzuJuV1:8aAvbyEATooiqrgAmH9zuJu7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F793F102A6909734C8B98F72106137208FA67775585B9BAFF49C944F7F2672183A37E1
sha3_384: 2ee21363ead35c6be1f9976df59eb24786ad1451ab0a7c798a326ed0440178e2612df12f3de80c4960a26ae796116f89
ep_bytes: ff250020400000000000000000000000
timestamp: 2072-12-13 02:29:57

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Override_Gui
FileVersion: 1.0.0.0
InternalName: Override_Gui.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: Override_Gui.exe
ProductName: Override_Gui
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ransom.BitRansomware also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Rents.4!c
Elasticmalicious (moderate confidence)
FireEyeGen:Heur.Ransom.REntS.Gen.1
McAfeeRDN/Generic.dx
MalwarebytesRansom.BitRansomware
BitDefenderGen:Heur.Ransom.REntS.Gen.1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HEHYBHO
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaTrojan:Win32/REntS.03a2b5e9
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
AvastWin32:Malware-gen
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
VIPREGen:Heur.Ransom.REntS.Gen.1
TrendMicroTROJ_GEN.R049C0PFD22
McAfee-GW-EditionRDN/Generic.dx
IkarusTrojan.SuspectCRC
GDataGen:Heur.Ransom.REntS.Gen.1
WebrootW32.Malware.Gen
MAXmalware (ai score=83)
ArcabitTrojan.Ransom.REntS.Gen.1
MicrosoftProgram:Win32/Wacapew.C!ml
AhnLab-V3Malware/Win.Generic.C5181550
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R049C0PFD22
RisingTrojan.Undefined!8.1327C (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat!tr.ransom
BitDefenderThetaGen:NN.ZemsilF.34786.fm0@a4gEhhb
AVGWin32:Malware-gen
Cybereasonmalicious.c142d6

How to remove Ransom.BitRansomware?

Ransom.BitRansomware removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment