Ransom Worm

About “Ransom.JSWorm” infection

Malware Removal

The Ransom.JSWorm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.JSWorm virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.JSWorm?


File Info:

crc32: 8014B693
md5: 31adc85947ddef5ce19c401d040aee82
name: 31ADC85947DDEF5CE19C401D040AEE82.mlw
sha1: 83fc6eb67db184d72c7f869a4798276add1b6932
sha256: 40753596e42b5d9114e00d959b96f76d3575f6624a85b4d4e68a4f1d2c037389
sha512: ae4e03abbdb4a5b9b8bdc935879d74b7143fa2f46458848eb4c2581180a4b3b1ccba1f1c99a3c12be66be9eaafcc942fcb75902abb6af220017e890466dd2f75
ssdeep: 1536:hMpzUI6GFG0ulaQcxbKeBDWouUitkXtoDiarKl:hMVOG8qb57HHar
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.JSWorm also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005588651 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop9.39759
CynetMalicious (score: 100)
ALYacTrojan.Ransom.JSWorm
CylanceUnsafe
ZillyaTrojan.Generic.Win32.924058
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/JSWorm.4f417f47
K7GWTrojan ( 005588651 )
Cybereasonmalicious.947dde
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.JSWorm.F
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.JSWORM.69D8B90B
NANO-AntivirusTrojan.Win32.Filecoder.ftvirn
ViRobotTrojan.Win32.Ransom.80896.B
MicroWorld-eScanDeepScan:Generic.Ransom.JSWORM.69D8B90B
TencentWin32.Trojan.Filecoder.Ljar
Ad-AwareDeepScan:Generic.Ransom.JSWORM.69D8B90B
SophosMal/Generic-S
BitDefenderThetaAI:Packer.5DFFB8591E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.JSWORM.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
FireEyeGeneric.mg.31adc85947ddef5c
EmsisoftDeepScan:Generic.Ransom.JSWORM.69D8B90B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gezwo
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2C3517B
MicrosoftRansom:Win32/JSWorm.A!MTB
ArcabitDeepScan:Generic.Ransom.JSWORM.69D8B90B
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Ransom.JSWORM.69D8B90B
TACHYONRansom/W32.JSWorm.80896
AhnLab-V3Trojan/Win32.RansomCrypt.C3360075
Acronissuspicious
McAfeeGenericRXAA-AA!31ADC85947DD
VBA32BScope.Trojan.Agent
MalwarebytesRansom.JSWorm
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.JSWORM.SMA
RisingTrojan.Generic@ML.89 (RDML:Oou1FRyE04D031qBf4WGhQ)
YandexTrojan.Filecoder!DylofGRLpKY
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Filecoder.NVV!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom.JSWorm?

Ransom.JSWorm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment