Ransom

Ransom.EasyRansom.1 (B) removal guide

Malware Removal

The Ransom.EasyRansom.1 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.EasyRansom.1 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity

How to determine Ransom.EasyRansom.1 (B)?


File Info:

name: 814544C44B46A5129CAD.mlw
path: /opt/CAPEv2/storage/binaries/319b4f65f140482aefd4dbe9431e9b77b90bbbcaf059a5c0ab83640e8e4ce14c
crc32: CD3AC9E7
md5: 814544c44b46a5129cad15bad0249c7e
sha1: bceb28a5601bf2800edf6efc70102633a01adfd4
sha256: 319b4f65f140482aefd4dbe9431e9b77b90bbbcaf059a5c0ab83640e8e4ce14c
sha512: ceaf0d4e404a77aede9863abdad429d1be7c0980aa947abecbeb0fb2787d44d3aa13ed432fcb06e7fc8b3e066ae974ebbeb24cc4e7831a6d8e66dd121c8e4008
ssdeep: 98304:80LgJ7xjo1kD1Kz0UmZESE3NFDlrAAK9O9eovgm8J+dOAhGEc1PDGvO:80gJ7x8qNUm+SeN9lrw25gm8yOOGE6P1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1114623632366014AD1E9CC3EC6377EE572F2037B8F4678B456DA69C1222A0F5E327953
sha3_384: 96e23cda9dc35f654e164d63809ff4d3b33ef916f08a3d36d126972c81dea7d44442978503bf7b9c23285f1bb79bfada
ep_bytes: 68d3ef2a5ce8243936008d3c17f9a9aa
timestamp: 2022-01-25 04:40:19

Version Info:

0: [No Data]

Ransom.EasyRansom.1 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Easy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.EasyRansom.1
FireEyeGeneric.mg.814544c44b46a512
McAfeeArtemis!814544C44B46
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/VMProtBad.662c3c5b
K7GWTrojan ( 7000001c1 )
K7AntiVirusTrojan ( 7000001c1 )
BitDefenderThetaGen:NN.ZexaF.34182.@FW@aui6skfi
CyrenW32/Agent.DPT.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CB222
ClamAVWin.Malware.Vmprotbad-9867392-0
BitDefenderGen:Variant.Ransom.EasyRansom.1
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Ransom.EasyRansom.1
EmsisoftGen:Variant.Ransom.EasyRansom.1 (B)
F-SecureHeuristic.HEUR/AGEN.1145252
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/VMProtBad-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.EasyRansom.1
AviraHEUR/AGEN.1145252
MAXmalware (ai score=83)
ArcabitTrojan.Ransom.EasyRansom.1
MicrosoftTrojan:Script/Phonzy.C!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.AGEN.C4482320
MalwarebytesTrojan.MalPack.VMP
APEXMalicious
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazqsdDt7/MyyRTkBp0GymmDF)
IkarusPUA.GameHack
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:Malware-gen
Cybereasonmalicious.5601bf

How to remove Ransom.EasyRansom.1 (B)?

Ransom.EasyRansom.1 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment