Ransom

How to remove “Ransom.Onion.A”?

Malware Removal

The Ransom.Onion.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Onion.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Creates a copy of itself
  • Appends a known Cerber ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics

Related domains:

crazyloading.cc
ww17.crazyloading.cc

How to determine Ransom.Onion.A?


File Info:

crc32: B12F4DC4
md5: 3c93f5734de703d7ad198d2dad3b7ca4
name: 3C93F5734DE703D7AD198D2DAD3B7CA4.mlw
sha1: e9e4531a8aa8275fbf9b0e480eaeacd4f5a932b3
sha256: c71384686c8caa0a72dcc7e0a4e93f56b8c66f9523fa1498ec9cf1794144ad70
sha512: eb12c08e4dbca51410c9cd52abe113f01b1951dbe1f13918f927d8c9545de423a27c4377f2ff919f901d5a91ba3f527c0d8e531514b5220f9bbb8bc4b374b35d
ssdeep: 3072:m8Dsp+FNX1dFOvDlXJulnN9loRPJUiupi2UoJlYlv:m8dNXSEdKRxV7KJlYlv
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Ransom.Onion.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 001f8f911 )
LionicTrojan.Win32.Sysn.b!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5054
CynetMalicious (score: 99)
CAT-QuickHealRansom.Onion.A
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
SangforRansom.Win32.Enestedel.B!rsm
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Enestedel.abcaa78b
K7GWTrojan ( 001f8f911 )
Cybereasonmalicious.34de70
SymantecPacked.NSISPacker!g6
ESET-NOD32Win32/Filecoder.Q
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.34057633
NANO-AntivirusTrojan.Win32.Inject.eeuokp
ViRobotTrojan.Win32.S.Cerber.127353
MicroWorld-eScanTrojan.GenericKD.34057633
TencentWin32.Trojan.Filecoder.Lmut
Ad-AwareTrojan.GenericKD.34057633
SophosMal/Generic-R + Mal/Miuref-L
ComodoMalware@#2mf1lj1871xu2
BitDefenderThetaGen:NN.ZedlaF.34058.dq4@a0vYjtn
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBERENC.SMNS1
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.cc
FireEyeGeneric.mg.3c93f5734de703d7
EmsisoftTrojan.GenericKD.34057633 (B)
SentinelOneStatic AI – Suspicious PE
WebrootTrojan.Dropper.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1F853D3
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Sorikrypt.A
SUPERAntiSpywareRansom.Cerber/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.34057633
AhnLab-V3Trojan/Win32.Cerber.C1502717
McAfeeArtemis!3C93F5734DE7
MAXmalware (ai score=100)
MalwarebytesMalware.AI.210415151
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBERENC.SMNS1
RisingTrojan.Generic@ML.100 (RDML:fWMWX41SYFv4vstcV4PEQQ)
YandexTrojan.Injector!FRIBotEAFuo
FortinetW32/Injector.DCKN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HyoD8DcA

How to remove Ransom.Onion.A?

Ransom.Onion.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment