Ransom

Ransom.Ranzy removal instruction

Malware Removal

The Ransom.Ranzy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Ranzy virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Ranzy?


File Info:

crc32: 9C7D80B2
md5: bbf6bbbd644c5f63bb6b3bc5dc9c8b8d
name: BBF6BBBD644C5F63BB6B3BC5DC9C8B8D.mlw
sha1: 35a663c2ce68e48f1a6bcb71dc92a86b36d4c497
sha256: 393fd0768b24cd76ca653af3eba9bff93c6740a2669b30cf59f8a064c46437a2
sha512: 2e6f07b398751405f5b28c523f002d96d743551925329f2df73f86a1be6b85b15ddff78f0d78f00df103d64db56cd021bd4a4ff5a0fc96ce8585b15a7df5e582
ssdeep: 3072:WNnBEPCZ788hExMfHg/50iIETyyCDRk8gE9QIluYEh0VZvcWrfF:WPEa586nHg/50/ET3CoE7uYEa1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Ranzy also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.Imps.1
CAT-QuickHealTrojanransom.Generic
McAfeeGenericRXLW-UE!BBF6BBBD644C
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.16457
AegisLabTrojan.Win32.DelShad.4!c
SangforMalware
K7AntiVirusTrojan ( 005700951 )
BitDefenderGen:Heur.Ransom.Imps.1
K7GWTrojan ( 005700951 )
Cybereasonmalicious.d644c5
ArcabitTrojan.Ransom.Imps.1
CyrenW32/Filecoder.AJ.gen!Eldorado
SymantecDownloader
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyHEUR:Trojan-Ransom.Win32.Generic
AlibabaRansom:Win32/FileCrypter.07d8b9d9
NANO-AntivirusTrojan.Win32.DelShad.hzjric
ViRobotTrojan,Win32.S.Ransom.141312
TencentMalware.Win32.Gencirc.11b01d8b
Ad-AwareGen:Heur.Ransom.Imps.1
EmsisoftTrojan.FileCoder (A)
ComodoMalware@#3hn27xouvu0ol
F-SecureTrojan.TR/AD.RansomHeur.oytef
DrWebTrojan.Encoder.32806
TrendMicroRansom.Win32.THUNDERX.SMTH
McAfee-GW-EditionGenericRXLW-UE!BBF6BBBD644C
FireEyeGeneric.mg.bbf6bbbd644c5f63
SophosMal/Generic-S
IkarusTrojan-Ransom.Ranzylocker
JiangminTrojan.DelShad.agq
WebrootW32.Ransom.Gen
AviraTR/AD.RansomHeur.oytef
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.DelShad
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Ransom.oa
MicrosoftRansom:Win32/FileCrypter.MB!MTB
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Heur.Ransom.Imps.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransomlock.R353561
VBA32BScope.Trojan.DelShad
ALYacTrojan.Ransom.Filecoder
MalwarebytesRansom.Ranzy
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Filecoder.RanzyLocker.A
TrendMicro-HouseCallRansom.Win32.THUNDERX.SMTH
RisingRansom.FileCrypter!8.11F42 (TFE:5:QDsKbiaRKNJ)
YandexTrojan.Filecoder!Grc/9E6H/XQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74279478.susgen
FortinetW32/Filecoder.ODD!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34634.iqW@aSoNd8ci
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.cc9

How to remove Ransom.Ranzy?

Ransom.Ranzy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment