Ransom

Ransom.Dharma.42 malicious file

Malware Removal

The Ransom.Dharma.42 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Dharma.42 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to delete volume shadow copies
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Dharma.42?


File Info:

crc32: 47417F3D
md5: 6144d17ff15e7172278f8018c7e035d5
name: 6144D17FF15E7172278F8018C7E035D5.mlw
sha1: 4ec66cc6672dd3182a02e2d701ca280bb6955c49
sha256: 7af7729649eff70e89ee1063042ab933f9cd9a6adcefab2a8d71766251e82e21
sha512: 158826fc20fd8e6cc65d5e9cddfce60c7d9fca942dab996f838748497f03513c6ee48651162f4ee30c75825a169a6237070225d922adcc100747fd6f1789715a
ssdeep: 12288:Wqf8SFWDfDnPDyyZTA6wQddSZK4H5RbyQH+CGe2tr8vA/t+eNM:Wqf8Fvd3dd+5hH+rtQIt+i
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: 2006-2014 (c) RimArts Inc.
CompanyName: RimArts Inc.
FileDescription: Ispostback Mitch
ProductName: Applies Compare
ProductVersion: 5.5.4.3
PrivateBuild: 5.5.4.3
OriginalFilename: Applies Compare
Translation: 0x0409 0x04b0

Ransom.Dharma.42 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053c7111 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3953
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Dharma.42
CylanceUnsafe
ZillyaAdware.Crusis.Win32.3
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Crusis.3e3f6c42
K7GWTrojan ( 0053c7111 )
Cybereasonmalicious.ff15e7
SymantecDownloader
ESET-NOD32a variant of Win32/Kryptik.GKTT
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crusis.csi
BitDefenderGen:Variant.Ransom.Dharma.42
NANO-AntivirusTrojan.Win32.Encoder.fhudft
MicroWorld-eScanGen:Variant.Ransom.Dharma.42
TencentWin32.Trojan.Crusis.Wlpc
Ad-AwareGen:Variant.Ransom.Dharma.42
SophosMal/Generic-S
ComodoMalware@#1n24x8ovxsbs1
BitDefenderThetaGen:NN.ZexaF.34608.XmKfaeMlGHji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.bc
FireEyeGeneric.mg.6144d17ff15e7172
EmsisoftGen:Variant.Ransom.Dharma.42 (B)
WebrootTrojan.Dropper.Gen
AviraTR/AD.Crysis.njygp
eGambitUnsafe.AI_Score_83%
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ransom.Dharma.42
AegisLabTrojan.Win32.Crusis.4!c
GDataGen:Variant.Ransom.Dharma.42
AhnLab-V3Malware/Win32.Generic.C4091288
McAfeeArtemis!6144D17FF15E
VBA32BScope.TrojanRansom.Foreign
MalwarebytesMalware.Heuristic.1003
PandaTrj/GdSda.A
RisingRansom.Crusis!8.5724 (CLOUD)
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.HAOZ!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.CrySiS.HgIASOUA

How to remove Ransom.Dharma.42?

Ransom.Dharma.42 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment