Ransom

Should I remove “Ransom.Mobef.2”?

Malware Removal

The Ransom.Mobef.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Mobef.2 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

keftiwrith.com
nodusnoser.net

How to determine Ransom.Mobef.2?


File Info:

crc32: 685C84EE
md5: a34ce4f0b40db525fd734511c4731fc6
name: A34CE4F0B40DB525FD734511C4731FC6.mlw
sha1: 727049f5b10bf1c1a2af00362f11896961a892c8
sha256: 44fa676771c713c3d042d4f0abf6b54dc7bff0f85fbeaee609f619be634a2302
sha512: 12bd78aa9d20ed6db44d851805678357a69b8e4f71abd9d6213025ed1c762874c25b3ee327c6fb9b43aaa09cb1d30d3b4121531ddffc87b100986f0e00f49508
ssdeep: 3072:b0cLqs3l1/N00XpJosD4gvG78fXLKL1JTptOBJJyL06c1t+Ht+i:b9NXpnD4gpXLKL1JTCBAA1Q
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2008-2010 ashampoo Technology GmbH Co. KG
InternalName: Cancel Autoplay 2
FileVersion: 2.0.0.0
CompanyName: Ashampoo
LegalTrademarks1: (
cel Autoplay 2: 0x06x01ProductVersion
.0: D
celAutoplay2.exe: Dx12x01ProductName
FileDescription: Cancel Autoplay 2
galTrademarks2: Px14x01OriginalFilename
Translation: 0x0409 0x04b0

Ransom.Mobef.2 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Mobef.2
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004ec6241 )
Cybereasonmalicious.0b40db
BaiduWin32.Trojan.Kryptik.anp
CyrenW32/Cerber.F.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Generik.FNKWFAO
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Mobef.2
NANO-AntivirusTrojan.Win32.Ransom.evksyf
MicroWorld-eScanGen:Variant.Ransom.Mobef.2
Ad-AwareGen:Variant.Ransom.Mobef.2
SophosML/PE-A + Mal/Ransom-EJ
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34744.jq0@amrGM9ci
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMCQ
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.a34ce4f0b40db525
EmsisoftGen:Variant.Ransom.Mobef.2 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bsgok
AviraTR/Crypt.ZPACK.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22D03A1
ArcabitTrojan.Ransom.Mobef.2
GDataGen:Variant.Ransom.Mobef.2
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeePacked-GZ!A34CE4F0B40D
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Cridex
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.SMCQ
RisingTrojan.Kryptik!1.AE9C (CLASSIC)
YandexTrojan.Agent!006ZSquLXKw
IkarusTrojan-PSW.Papras
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HCAW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.Mobef.2?

Ransom.Mobef.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment