Ransom

What is “Ransom.Demo”?

Malware Removal

The Ransom.Demo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Demo virus can do?

  • Anomalous binary characteristics

How to determine Ransom.Demo?


File Info:

crc32: 0B63AAFB
md5: 55d4a47927b3ac6da49f998ab6289f42
name: 55D4A47927B3AC6DA49F998AB6289F42.mlw
sha1: d5d20d92e715fae67b1af2ce01a47efe43f40b95
sha256: 3f683ab5330135b74ce98a880b3f6f872054d51031d6b64dadac8eeae33a771f
sha512: a45457a8a0276e3de0aee2bab254b6e4b4a396ed309f99ec006422a52040ecbc5a5dd6f4afb6fa61feab0aba7f41b90e43bdb53fe8c5d27f50c0a196c79f40ec
ssdeep: 6144:U5Zza7ALpvWwGGiAP2S7Bh1C0xwazud3WiBmGiasFyQva80TbA4d:2Z+59J657XM0Na4vplFFvXqd
type: PE32+ executable (console) x86-64, for MS Windows

Version Info:

0: [No Data]

Ransom.Demo also known as:

K7AntiVirusTrojan ( 005659041 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31674
CynetMalicious (score: 90)
ALYacTrojan.Ransom.CDS
CylanceUnsafe
ZillyaTrojan.Filecoder.Win64.9044
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Filecoder.f9c3e911
K7GWTrojan ( 005659041 )
Cybereasonmalicious.927b3a
SymantecTrojan.Gen.2
ESET-NOD32Win64/Filecoder.BQ
APEXMalicious
AvastWin64:Trojan-gen
KasperskyTrojan.Win32.DiskWriter.epz
BitDefenderTrojan.Ransom.CDS
MicroWorld-eScanTrojan.Ransom.CDS
TencentMalware.Win32.Gencirc.1167ad38
Ad-AwareTrojan.Ransom.CDS
ComodoMalware@#18x6pq833t8fc
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.55d4a47927b3ac6d
EmsisoftTrojan.Ransom.CDS (B)
SentinelOneStatic AI – Suspicious PE
JiangminHoax.FakeRansom.ai
WebrootW32.Trojan.Gen
AviraTR/FileCoder.gqbhy
MicrosoftRansom:Win32/Filecoder.YA!MTB
ArcabitTrojan.Ransom.CDS
AegisLabTrojan.Win32.Filecoder.4!c
ZoneAlarmTrojan.Win32.DiskWriter.epz
GDataTrojan.Ransom.CDS
TACHYONRansom/W64.Agent.337188
AhnLab-V3Malware/Win64.Generic.C4109320
McAfeeArtemis!55D4A47927B3
MAXmalware (ai score=100)
VBA32Trojan.Encoder
MalwarebytesRansom.Demo
PandaTrj/CI.A
RisingRansom.Filecoder!8.55A8 (CLOUD)
IkarusTrojan.Win64.Meterpreter
MaxSecureTrojan.Malware.97660284.susgen
FortinetW32/Filecoder.BQ!tr.ransom
AVGWin64:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win64/Ransom.Filecoder.HgEASOgA

How to remove Ransom.Demo?

Ransom.Demo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment