Ransom

How to remove “Ransom.Erica”?

Malware Removal

The Ransom.Erica is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Erica virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Ransom.Erica?


File Info:

crc32: 1CD94EF5
md5: 480b11112bd4b0a3c7588c9e6af00b28
name: 480B11112BD4B0A3C7588C9E6AF00B28.mlw
sha1: 65b53387b9f7abeb406675c16e6fecfc270482fc
sha256: 0cb062a6741924845c58c33bf8b94b7e8d6b4d71d4cd3ceda53c730f9b178369
sha512: 4d288cc98cab917e2e60cb1744063f5d0526ab52aa32fd64033deb642c9baaddc737b275a495534bcc980f644cf10de53cfb50db4752a07edca71f553e96a6e6
ssdeep: 1536:zRNAfLOk58VHlA30ZbmzczojW7BBL6EY4FqKRX5Oh+XD:zRNi75QHmkV2cWW7BBnFqKU+X
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom.Erica also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Strictor.252131
FireEyeGeneric.mg.480b11112bd4b0a3
ALYacGen:Variant.Strictor.252131
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Strictor.252131
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZelphiF.34658.dmGfa0fJYtec
CyrenW32/Trojan.LNTM-9181
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OES
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Delf.sr
AlibabaRansom:Win32/Filecoder.2c6a2586
ViRobotTrojan.Win32.Z.Zusy.56832.CD
Ad-AwareGen:Variant.Strictor.252131
SophosMal/Generic-S
F-SecureTrojan.TR/Delf.Agent.vzbko
DrWebTrojan.Encoder.33259
TrendMicroRansom_Delf.R06EC0WKU20
McAfee-GW-EditionBehavesLike.Win32.Dropper.qc
EmsisoftGen:Variant.Strictor.252131 (B)
IkarusTrojan.BadJoke.FakeKAV
AviraTR/Delf.Agent.vzbko
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Ymacco.AA0C
ArcabitTrojan.Strictor.D3D8E3
ZoneAlarmTrojan-Ransom.Win32.Delf.sr
GDataGen:Variant.Strictor.252131
CynetMalicious (score: 100)
McAfeeRDN/GenericM
MalwarebytesRansom.Erica
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Delf.R06EC0WKU20
RisingMalware.Undefined!8.C (TFE:5:GTR5N3WIifT)
eGambitUnsafe.AI_Score_59%
FortinetPossibleThreat.MU
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM11.1.8BD2.Malware.Gen

How to remove Ransom.Erica?

Ransom.Erica removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment