Ransom

Ransom.Pluto removal tips

Malware Removal

The Ransom.Pluto is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Pluto virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • A process created a hidden window
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
myexternalip.com
ocsp.pki.goog
api.db-ip.com

How to determine Ransom.Pluto?


File Info:

crc32: 935402F6
md5: 3bdbe5d74c2f91000aa166ea4ec47de6
name: 3BDBE5D74C2F91000AA166EA4EC47DE6.mlw
sha1: d4b6ad71da2ce6698dbdeed029f6c4e7410ba149
sha256: c9fb0e9642eba331b1de6b156a8ba9d4e0152c67970185e4505debc361e5937f
sha512: 9e95dbe7191a9e0c390f64ca3ec4e28801f059628fa84fb05db6eb9024118766771f78abcddd0c1bfdbf2e2c16d8e7320494e620a1949d55dfd39a20951117c2
ssdeep: 1536:y1KZb+iQy5iSJsIj4O8NiUIe+4XrPmPVCkWrLoC/XNcEMVtntu:KKZqiD9qIELN5f3gVorLjDMVN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Pluto also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00566c1d1 )
LionicTrojan.Win32.Nemty.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31950
CynetMalicious (score: 100)
ALYacTrojan.Ransom.PLUTO
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Genasom.ali1000102
K7GWTrojan ( 00566c1d1 )
Cybereasonmalicious.74c2f9
ESET-NOD32a variant of Win32/Filecoder.Nemty.F
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.JSWorm.cp
BitDefenderGeneric.Ransom.Nemty.D935C821
NANO-AntivirusTrojan.Win32.DelShad.isibdz
MicroWorld-eScanGeneric.Ransom.Nemty.D935C821
TencentWin32.Trojan.Delshad.Lnyp
Ad-AwareGeneric.Ransom.Nemty.D935C821
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34790.fqW@a84WAap
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXKW-ZD!3BDBE5D74C2F
FireEyeGeneric.mg.3bdbe5d74c2f9100
EmsisoftGeneric.Ransom.Nemty.D935C821 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Redcap.yyscs
Antiy-AVLTrojan/Generic.ASMalwS.3087330
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/FileCoder.D!MTB
ArcabitGeneric.Ransom.Nemty.D935C821
GDataGeneric.Ransom.Nemty.D935C821
AhnLab-V3Trojan/Win32.Nemty.C4108985
McAfeeGenericRXKW-ZD!3BDBE5D74C2F
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Cryptor
MalwarebytesRansom.Pluto
PandaTrj/GdSda.A
RisingRansom.NEFILIM!1.C3E7 (CLASSIC)
IkarusTrojan-Ransom.Nemty
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Nemty.F!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HgIASOkA

How to remove Ransom.Pluto?

Ransom.Pluto removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment