Ransom

Should I remove “Ransom.Karo”?

Malware Removal

The Ransom.Karo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Karo virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

Related domains:

dist.torproject.org
apps.identrust.com

How to determine Ransom.Karo?


File Info:

crc32: 1CF7BAF3
md5: 4e2273bca8389e2b57077e5e8cbd6f5f
name: 4E2273BCA8389E2B57077E5E8CBD6F5F.mlw
sha1: 51d4a2db8d10b76f44b08f88db7353d4c8db360c
sha256: 7f081859ae2b9b59f014669233473921f1cac755f6c6bbd5dcdd3fafbe710000
sha512: acc35caed138726d921f3458f8e7a6cfd2e106b5eb3d340005505f2b5076dbda3d62b7efb76ab39facc4358e4c81aafbd0b747b2d505727046b5f8fe051f4c55
ssdeep: 12288:VPM2o477B1ei2ePqvL8YSqk6pPBoqQ0ONnV7wIV7uikFg:uu7B1HqvL8YS4zQbNV7wIlubg
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Ransom.Karo also known as:

K7AntiVirusTrojan ( 00510dbd1 )
LionicTrojan.Win32.TorJok.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.12461
CynetMalicious (score: 100)
CAT-QuickHealRansom.Petya.S1164450
ALYacTrojan.Ransom.Karo
CylanceUnsafe
ZillyaTrojan.TorJok.Win32.2
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/TorJok.3851402a
K7GWTrojan ( 00510dbd1 )
Cybereasonmalicious.ca8389
CyrenW32/Trojan.QHTK-3047
SymantecRansom.Karo
ESET-NOD32MSIL/Filecoder.II
ZonerTrojan.Win32.60472
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Karo-6331638-1
KasperskyTrojan.Win32.TorJok.k
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.TorJok.eqlvii
ViRobotTrojan.Win32.S.Ransom.720896
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
TencentMalware.Win32.Gencirc.10ba13ab
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosMal/Generic-R + Mal/Karo-A
ComodoMalware@#2gi4bkvzzfbx
BitDefenderThetaGen:NN.ZemsilF.34796.Sm0@aGTeDlg
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_KARO.A
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGen:Heur.MSIL.Bladabindi.1
EmsisoftTrojan-Ransom.Karo (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.TorJok.f
WebrootW32.Malware.Gen
AviraTR/FileCoder.cmyva
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.20E7522
KingsoftWin32.Troj.Ransome.a.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.FW!MTB
SUPERAntiSpywareRansom.Karo/Variant
GDataWin32.Trojan.Agent.7K0X4N
AhnLab-V3Trojan/Win32.FileCryptor.C2019718
McAfeeGeneric.acn
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesRansom.Karo
PandaTrj/WLT.C
TrendMicro-HouseCallRansom_KARO.A
YandexTrojan.TorJok!/qWf1FJ2dWw
IkarusTrojan-Ransom.Karo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/TorJok.II!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HwMAEpsA

How to remove Ransom.Karo?

Ransom.Karo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment