Ransom

Ransom.Quimera (file analysis)

Malware Removal

The Ransom.Quimera is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Quimera virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine Ransom.Quimera?


File Info:

crc32: 17F49CB9
md5: 23fb59ad1eb4be42f91c3d58c63ac67b
name: tmpkwe8alf_
sha1: bfab165c6ed93f6dae1eb154a6d8a64cc788b6d3
sha256: 049425dac929baf288c44c981ef63417d097fb95f5199c9f33e5ef5e2ec20590
sha512: f615e023c4d8f4def4962f0624e19ad1bed5c40aa355dcf32a64dc8f8a3d8ff27e539ff94e8849d4efcb5f4422cf45e6d27a2e0382394e03f198ab7ea6195637
ssdeep: 768:xadHo/Q1rTUJw7v7Mj7bdFcEcMONqGCrtEEzRhkBzHBr2ckP2bpVkV5EPzOK4k:SHo/UU+7KdWB+G41hQzHJ2v2bpVygG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 2019 vHnLRJ0ti4ni
Assembly Version: 4.5.0.0
InternalName: PZB8ZycM4heY
FileVersion: 4.5.0.0
CompanyName: fnEy93lTHQhB HhG1dlBEFZ81
LegalTrademarks: XF7eIAwcM5Bh g759zm1GoNC1
ProductName: su6IEmyYk0r7
ProductVersion: 4.5.0.0
FileDescription: Memory Operator
OriginalFilename: og6FngpzGGpU

Ransom.Quimera also known as:

MicroWorld-eScanTrojan.GenericKD.42840578
FireEyeGeneric.mg.23fb59ad1eb4be42
CAT-QuickHealTrojan.Wacatac
Qihoo-360Generic/Trojan.f5a
McAfeeRDN/Ransom
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.13338
K7AntiVirusTrojan ( 0055ef9f1 )
AlibabaTrojan:MSIL/Filecoder.b8532609
K7GWTrojan ( 0055ef9f1 )
Cybereasonmalicious.c6ed93
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Filecoder.Thanos.A
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42840578
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.42840578
NANO-AntivirusTrojan.Win32.DelShad.hfwijm
ViRobotTrojan.Win32.Z.Filecoder.64960
AvastWin32:Malware-gen
TencentWin32.Trojan.Falsesign.Hssx
Ad-AwareTrojan.GenericKD.42840578
SophosMal/Generic-S
ComodoMalware@#4f5xpeyc4vy2
F-SecureHeuristic.HEUR/AGEN.1123489
DrWebTrojan.Siggen9.21820
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.MSIL.ONTAI.A
McAfee-GW-EditionRDN/Ransom
EmsisoftTrojan.GenericKD.42840578 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.ZIQC-8989
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1123489
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28DB202
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.MSIL.DelShad.gen
MicrosoftRansom:MSIL/Hakbit.SK!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_RansomCrypt.C4035688
VBA32TScope.Trojan.MSIL
ALYacTrojan.Ransom.Filecoder
MAXmalware (ai score=98)
MalwarebytesRansom.Quimera
TrendMicro-HouseCallRansom.MSIL.ONTAI.A
RisingRansom.Hakbit!8.11A3B (CLOUD)
YandexTrojan.Filecoder!BL/+eKQA3w0
IkarusTrojan-Ransom.FileCrypter
eGambitPE.Heur.InvalidSig
FortinetMSIL/Filecoder.VL!tr.ransom
BitDefenderThetaGen:NN.ZemsilF.34128.dm2@aqWzNxm
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.74133646.susgen

How to remove Ransom.Quimera?

Ransom.Quimera removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment