Ransom

About “Ransom.Exorcist” infection

Malware Removal

The Ransom.Exorcist is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Exorcist virus can do?

  • Expresses interest in specific running processes
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Creates a hidden or system file
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Exorcist?


File Info:

crc32: 6922615D
md5: 9e5c89c84cdbf460fc6857c4e32dafdf
name: upload_file
sha1: ee0a95846ce48c59261eda0fdd6b38dfc83d9f4d
sha256: dfecb46078038bcfa9d0b8db18bdc0646f33bad55ee7dd5ee46e61c6cf399620
sha512: 6da517ae5159ebcb0ac138b34215924fb21adae619c3c15ede6863866648e445633f482b2beaddbe74de66b48e18d106dbde3253ee2d3ce86da667f7f8494cd8
ssdeep: 1536:7ufJPTAoUei1obcxtZbW3BqlIS2IyUY4h2wEsOolJT+y9v:7upTAneif03BqarUY4l
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Exorcist also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Razy.13274
FireEyeGeneric.mg.9e5c89c84cdbf460
Qihoo-360Generic/Trojan.92d
ALYacTrojan.Ransom.Exorcist
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Razy.4!c
SangforMalware
K7AntiVirusTrojan ( 0056f8591 )
BitDefenderGen:Variant.Ser.Razy.13274
K7GWTrojan ( 0056f8591 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTrojan.Win32.WACATAC.THIBDBO
SymantecDownloader
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.DelShad.ezt
AlibabaTrojan:Win32/DelShad.0954a167
ViRobotTrojan.Win32.Z.Ser.69632
RisingTrojan.Generic@ML.97 (RDML:qsoO/Bd9C77uYZuK3MvlsQ)
Ad-AwareGen:Variant.Ser.Razy.13274
EmsisoftGen:Variant.Ser.Razy.13274 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Encoder.32637
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Ransom.Exorcist
WebrootW32.Trojan.AADF
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Ymacco.AADF
ArcabitTrojan.Ser.Razy.D33DA
ZoneAlarmTrojan.Win32.DelShad.ezt
GDataGen:Variant.Ser.Razy.13274
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Razy.C4199846
McAfeeGenericRXMB-MR!9E5C89C84CDB
MAXmalware (ai score=99)
MalwarebytesRansom.Exorcist
PandaTrj/GdSda.A
ESET-NOD32Win32/Filecoder.Exorcist.B
TrendMicro-HouseCallTrojan.Win32.WACATAC.THIBDBO
TencentWin32.Trojan.Filecoder.Hvtc
FortinetW32/Filecoder_Exorcist.B!tr.ransom
BitDefenderThetaAI:Packer.A72B25011E
AVGWin32:Malware-gen
Cybereasonmalicious.84cdbf
Paloaltogeneric.ml

How to remove Ransom.Exorcist?

Ransom.Exorcist removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment