Fake Ransom

Should I remove “Ransom.FakeSig”?

Malware Removal

The Ransom.FakeSig is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.FakeSig virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
geoiptool.com
www.geodatatool.com
ocsp.comodoca.com
ocsp.usertrust.com
crl.usertrust.com

How to determine Ransom.FakeSig?


File Info:

crc32: A18D8F97
md5: 9993dc8dfabca3331e3d9b15dc10928d
name: 9993DC8DFABCA3331E3D9B15DC10928D.mlw
sha1: 8c529a8d526b50ddf5e2c66b591feb1f444acffe
sha256: 778f30d268f051802cd3b1fe3f8a4bd010f7ab3dae1dc4e6073c0b2f972effb0
sha512: 907dc2d6851d9d4e628c272108f5a12b67cd547e74db40450e8141c6ff5179c858cb7021430abd8d440c220707e8a4eecc013b18bfd9f6747d8f0d2bfc3cdf0e
ssdeep: 12288:9Y20AljdZgBPfKfY8qQxAogJfqsUsz0cX0kJ9tdr95aj:S20gPgFKA8qQxAVBbIcXj9tdZC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.FakeSig also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.Encoder.33333
MicroWorld-eScanGeneric.Ransom.Buhtrap.4D947393
ALYacTrojan.Ransom.VegaLocker
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Generic.29a12777
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.dfabca
SymantecDownloader
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Vega.an
BitDefenderGeneric.Ransom.Buhtrap.4D947393
NANO-AntivirusTrojan.Win32.Vega.iexzsa
TencentWin32.Trojan.Falsesign.Hvix
SophosMal/Generic-S (PUA)
TrendMicroTROJ_FRS.VSNTA721
McAfee-GW-EditionRDN/Ransom
FireEyeGeneric.Ransom.Buhtrap.4D947393
EmsisoftGeneric.Ransom.Buhtrap.4D947393 (B)
JiangminTrojan.Scar.roh
AviraTR/Redcap.usjri
eGambitPE.Heur.InvalidSig
MicrosoftProgram:Win32/Ymacco.AA77
ArcabitGeneric.Ransom.Buhtrap.4D947393
AegisLabTrojan.Win32.Vega.j!c
ZoneAlarmTrojan-Ransom.Win32.Vega.an
GDataGeneric.Ransom.Buhtrap.4D947393
AhnLab-V3Malware/Win32.Generic.C4293578
McAfeeRDN/Ransom
MAXmalware (ai score=99)
MalwarebytesRansom.FakeSig
TrendMicro-HouseCallTROJ_FRS.VSNTA721
IkarusTrojan.Inject
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.FakeSig?

Ransom.FakeSig removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment