Ransom

Should I remove “Ransom.MZR.2”?

Malware Removal

The Ransom.MZR.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.MZR.2 virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify UAC prompt behavior
  • Uses suspicious command line tools or Windows utilities

Related domains:

df4gd65fg4565f4d56.000webhostapp.com

How to determine Ransom.MZR.2?


File Info:

crc32: BE13D31D
md5: 8ab4b4a5bb74f22137e45a15879c9f9b
name: 8AB4B4A5BB74F22137E45A15879C9F9B.mlw
sha1: 34910961fb2a694e3a49057fbe919cd3e527fe66
sha256: a7a64650030f5d2225d4c742b8bd6af03f5db691ebe153ef99452fbe5b315f9e
sha512: 25d7c8d9dec32850f134aab80026e2adf8977747ac66a19c6e4ebdf28e0ae2315861a1a3285525a3191ef317ad99e5e7437265534e05ecfde75e1ba5a37ef33a
ssdeep: 12288:27BkzBYkIkTd/jKie8r+9pIOo/04K6PoItUAWZWO6Id6o0yofJ06OAz2loNBHg:ABMPImJjde8iiO2dPoItUAW34o086la
type: MS-DOS executable, MZ for MS-DOS

Version Info:

ProgramID: FFFFFFFFFFFFFFF
ProductName: FFFFFFFFFFFFFFF
FileVersion: 2.0.0.0
ProductVersion: 2.0.0.0
FileDescription: FFFFFFFFFFFFFFF
Translation: 0x0407 0x04e4

Ransom.MZR.2 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055d3ed1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.18538
CynetMalicious (score: 99)
CAT-QuickHealTrojan.GenericPMF.S11930899
ALYacTrojan.Ransom.DenizKizi
CylanceUnsafe
AlibabaRansom:Win32/Filecoder.8bd19538
K7GWTrojan ( 0055d3ed1 )
Cybereasonmalicious.5bb74f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NZK
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan-Ransom.Win32.Wanna.gen
BitDefenderGen:Variant.Ransom.MZR.2
NANO-AntivirusTrojan.Win32.Wanna.heppuj
MicroWorld-eScanGen:Variant.Ransom.MZR.2
TencentWin32.Trojan.Filecoder.Ednw
Ad-AwareGen:Variant.Ransom.MZR.2
SophosMal/Generic-R + Mal/TinyDL-T
BitDefenderThetaGen:NN.ZelphiF.34738.SmuaayJZuxhi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.KIZI.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.8ab4b4a5bb74f221
EmsisoftGen:Variant.Ransom.MZR.2 (B)
AviraHEUR/AGEN.1132041
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.301BE6B
MicrosoftRansom:Win32/Kizi!MSR
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Variant.Ransom.MZR.2
AhnLab-V3Malware/Win32.RL_Ransom.R329049
McAfeeGenericRXAA-AA!8AB4B4A5BB74
MAXmalware (ai score=83)
VBA32TrojanRansom.Wanna
MalwarebytesRansom.Mamo
PandaTrj/CI.A
TrendMicro-HouseCallRansom.Win32.KIZI.SMTH
RisingTrojan.Disabler!1.CAB8 (CLASSIC)
YandexTrojan.GenAsa!fM7E956dROE
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.NZK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.MZR.2?

Ransom.MZR.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment