Categories: Ransom

How to remove “Ransom.Ouroboros”?

The Ransom.Ouroboros is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Ouroboros virus can do?

  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Ouroboros?


File Info:

crc32: DB2EAF09md5: 99437e23412a7743a2c4fb0686d991d7name: tmps5s4009dsha1: ec1dde2b1dfc44782786d22fb20e7af4d1c6dac3sha256: 4943b1d2e9d94c595fdb1d9f5d71e104547b95bde44ce18ff9048beeea650e9csha512: 360ed123fea4bea3525d6a804c46219916054b03af126d4f5f1cfbaeb36753ed1bea3dadfb7221e6143d329d3988bcba9389e9a0e20050474ee71bf2dd29f9ddssdeep: 24576:9h5bh2d+xkWndnnYcca+RXYZ0cap2IwufOObKgr9H1aL:9hphXNdnY3YdtI5tKYN1aLtype: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Ouroboros also known as:

Bkav W32.AIDetectVM.malware1
MicroWorld-eScan Generic.Ransom.Ouroboros.5D288861
CAT-QuickHeal Ransom.Ouroboros
McAfee GenericRXAA-AA!99437E23412A
Sangfor Malware
Cybereason malicious.3412a7
Arcabit Generic.Ransom.Ouroboros.5D288861
TrendMicro Ransom.Win32.OUROBOROS.SMD
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Filecoder.Ouroboros.E
APEX Malicious
ClamAV Win.Ransomware.Ouroboros-7689029-0
GData Generic.Ransom.Ouroboros.5D288861
Kaspersky HEUR:Trojan-Ransom.Win32.Limbozar.vho
BitDefender Generic.Ransom.Ouroboros.5D288861
NANO-Antivirus Trojan.Win32.Limbozar.hezuku
Ad-Aware Generic.Ransom.Ouroboros.5D288861
DrWeb Trojan.DownLoader33.15004
FireEye Generic.mg.99437e23412a7743
Emsisoft Generic.Ransom.Ouroboros.5D288861 (B)
SentinelOne DFI – Suspicious PE
Jiangmin Trojan.Crypren.xg
Webroot W32.Trojan.Gen
Antiy-AVL Trojan[Ransom]/Win32.Limbozar
Microsoft Ransom:Win32/Ouroboros.GG!MTB
Endgame malicious (high confidence)
ZoneAlarm HEUR:Trojan-Ransom.Win32.Limbozar.vho
AhnLab-V3 Malware/Win32.RL_Ransom.R329075
BitDefenderTheta Gen:NN.ZexaF.34130.@uW@aKhvMtfi
ALYac Generic.Ransom.Ouroboros.5D288861
MAX malware (ai score=80)
VBA32 BScope.Trojan.DelShad
Malwarebytes Ransom.Ouroboros
TrendMicro-HouseCall Ransom.Win32.OUROBOROS.SMD
Rising Ransom.Ouroboros!8.113A9 (TFE:dGZlOgU5vbbq2GU5zA)
Yandex Trojan.Filecoder!sRj9o0RHCRo
Ikarus Trojan-Ransom.Ouroboros
eGambit Unsafe.AI_Score_100%
Fortinet W32/Ouroboros.D!tr.ransom
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
Qihoo-360 HEUR/QVM19.1.2373.Malware.Gen

How to remove Ransom.Ouroboros?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

VHO:RiskTool.Win32.ProcPatcher information

The VHO:RiskTool.Win32.ProcPatcher is considered dangerous by lots of security experts. When this infection is active,…

29 mins ago

Lazy.280688 removal guide

The Lazy.280688 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.3454153382 information

The Malware.AI.3454153382 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Midie.100502 removal tips

The Midie.100502 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

Malware.AI.3915743673 (file analysis)

The Malware.AI.3915743673 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

Malware.AI.2034266737 removal

The Malware.AI.2034266737 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago