Ransom

Ransom.Sage.63 removal guide

Malware Removal

The Ransom.Sage.63 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Sage.63 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Sage.63?


File Info:

crc32: C1FEC2FD
md5: b4b4b89061f4965564fb1ccbb56208e7
name: B4B4B89061F4965564FB1CCBB56208E7.mlw
sha1: a90631be98bc501ab519d328ec24224a1d598c92
sha256: 5d6c7038d900cf8f5294429c5a8c822d94a880d2c4623abf835f74d6edc4ef23
sha512: 2ef58c7b3fd40d14ad5a5690ebf520039b5beee7d3156b47ff47ff98ca3f5c596c4548e83274040a9526d38780d754910e712657f2d8774cd581041e4bee502e
ssdeep: 6144:+ejm5bId8VvcnCYPSg7QymoZL3xrVwBy1FUKlOV:+eC5bIdSvcCYPSgEsZdrTUj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Just Great Software Copyright xa9. 1999 - 2014
InternalName: WreakMultiprocessor
CompanyName: Just Great Software
ProductName: WreakMultiprocessor
ProductVersion: 6.9.1.4
FileDescription: Powerfully That's Concurrent
OriginalFilename: WreakMultiprocessor
Translation: 0x0409 0x04b0

Ransom.Sage.63 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sage.63
McAfeeArtemis!B4B4B89061F4
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderGen:Variant.Ransom.Sage.63
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sage.63
EmsisoftGen:Variant.Ransom.Sage.63 (B)
ComodoMalware@#2dzcu2haewc7v
F-SecureHeuristic.HEUR/AGEN.1140130
TrendMicroRansom_HPLOCKY.SME1
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.b4b4b89061f49655
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1140130
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Ransom.Sage.63
GDataGen:Variant.Ransom.Sage.63
CynetMalicious (score: 85)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.qq0@aSRvZJoi
MAXmalware (ai score=100)
VBA32BScope.Trojan-Ransom.Foreign
MalwarebytesMachineLearning/Anomalous.93%
ESET-NOD32a variant of Win32/Kryptik.FNKJ
TrendMicro-HouseCallRansom_HPLOCKY.SME1
TencentWin32.Trojan.Symmi.Pgcq
YandexTrojan.Kryptik!0T0A3+AGj3I
IkarusTrojan-Spy.Remcos
eGambitUnsafe.AI_Score_100%
FortinetW32/Kryptik.EJXP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.5c7

How to remove Ransom.Sage.63?

Ransom.Sage.63 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment