Ransom

Ransom.Magniber removal

Malware Removal

The Ransom.Magniber is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Magniber virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Lithuanian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Mimics the file times of a Windows system file
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Magniber?


File Info:

crc32: 082DD810
md5: 2cec337ea5ac527e67370535efeb2714
name: 2CEC337EA5AC527E67370535EFEB2714.mlw
sha1: 7cf4436896590e5d2006345b51105ff797498736
sha256: c7cbef1805492cc0c90a58f8f8a9ece7a41e99a26ee763e63bc01857a927aa2a
sha512: 34244140b09bcc7ccfebf03524030a1dd0f46a4f49845aaba6a39ed7874a3c8cd01f069786123246490845cf37002701481e41f35161239701b7d409d0261e62
ssdeep: 3072:TY1vPmR1QwTsnvAOdIepOfCY5iUj8XJETZ4:TY1vU1HmIAC5ra1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, sdfsg
FileVersion: 1.0.0.1
ProductVersion: 1.0.0.1
Translation: 0x0809 0x04b0

Ransom.Magniber also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00539ed31 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.15065
CynetMalicious (score: 100)
ALYacTrojan.BRMon.Gen.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Diple.6454ccd2
K7GWAdware ( 00539ed31 )
Cybereasonmalicious.ea5ac5
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.FYZI
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Emotet-6398523-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.1
NANO-AntivirusTrojan.Win32.SpyEyes.euyfpg
SUPERAntiSpywareTrojan.Agent/Gen-Multi
MicroWorld-eScanTrojan.BRMon.Gen.1
TencentMalware.Win32.Gencirc.10ba97d5
Ad-AwareTrojan.BRMon.Gen.1
SophosMal/Generic-S + Mal/GandCrab-D
ComodoTrojWare.Win32.Crypt.AX@7g0nea
BitDefenderThetaGen:NN.ZexaF.34686.ny0@aG8CvxbO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.2cec337ea5ac527e
EmsisoftTrojan.BRMon.Gen.1 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Win32/Diple.B!bit
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.1
AhnLab-V3Trojan/Win32.Magniber.C2258729
Acronissuspicious
McAfeeTrojan-FOSS!2CEC337EA5AC
MAXmalware (ai score=100)
VBA32Trojan.qnz
MalwarebytesRansom.Magniber
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
YandexTrojan.GenAsa!t/jvnKVgH1g
IkarusTrojan.Win32.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.BCYP!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom.Magniber?

Ransom.Magniber removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment