Ransom

Ransom.Marvel removal instruction

Malware Removal

The Ransom.Marvel is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Marvel virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Marvel?


File Info:

crc32: 43B713EF
md5: e37548d5f4767a9346e12c865e7d80f7
name: E37548D5F4767A9346E12C865E7D80F7.mlw
sha1: ea272e9d018454dff0f6640f46c42e06e3a22b8d
sha256: 53949ef3e26fbae3d1db568a0857849d466a39bb3dc51c9a62c2bcb735163f80
sha512: abf744c7dfac27e2c29743f38b6b7dfd5a91b9bf4621fec07a9e3ffe7300c9d65495546721a9e60eee07a61d0bc44a2c8ac2067e89155fc00b3ccde94f555d19
ssdeep: 6144:0KN0jnx1YhojThPfaayk7qvC5hjxXxf/LyvlcSSVlDkT:0DjpZPfaaDiC7xBHmv0DO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom.Marvel also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d4981 )
LionicTrojan.Win32.DelShad.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop11.51709
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.14339
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/DelShad.c62c89cb
K7GWTrojan ( 00528d051 )
Cybereasonmalicious.5f4767
CyrenW32/Ransom.ND.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Filecoder.NPI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.DelShad.cvx
BitDefenderGeneric.Ransom.Mole.CD9EA986
NANO-AntivirusTrojan.Win32.DelShad.hgqlno
MicroWorld-eScanGeneric.Ransom.Mole.CD9EA986
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.Mole.CD9EA986
SophosMal/Generic-S
ComodoMalware@#3atlcpa34nubk
BitDefenderThetaAI:Packer.59159EAC1F
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Higuniel.R002C0DF621
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.e37548d5f4767a93
EmsisoftGeneric.Ransom.Mole.CD9EA986 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.DelShad.vk
AviraHEUR/AGEN.1135904
Antiy-AVLTrojan/Generic.ASMalwS.30480EE
MicrosoftRansom:Win32/Higuniel.A
ArcabitGeneric.Ransom.Mole.CD9EA986
GDataGeneric.Ransom.Mole.CD9EA986
AhnLab-V3Trojan/Win32.Generic.C4057553
McAfeeRDN/Ransom
MAXmalware (ai score=100)
VBA32BScope.Trojan.MulDrop
MalwarebytesRansom.Marvel
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Higuniel.R002C0DF621
RisingRansom.Agent!1.C60A (CLASSIC)
YandexTrojan.Filecoder!O0+kidlWRKc
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.85031174.susgen
FortinetW32/Filecoder.NPI!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom.Marvel?

Ransom.Marvel removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment