Ransom

Ransom.Satan malicious file

Malware Removal

The Ransom.Satan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Satan virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Satan?


File Info:

crc32: DCEA3D1B
md5: 0afa321c36913d27103e33ce3c943314
name: 0AFA321C36913D27103E33CE3C943314.mlw
sha1: 12faaf2d6633f9495a12791f6f12cf47096063fd
sha256: c26e2988426be5915c498f9dde7a455fac9c57472601fb7f48b851c024cd65d1
sha512: 116ea7c5f5d86a264b6d2b76a34b490cea73e1ee806e1799a2e1a1653dc6590f10326cdd75ad827e80b1c0afee736789243c175f77a5506b2c9e40f8daeb57c5
ssdeep: 1536:7X2CPX5PejT1iDYK7Uz96KyF+VksrCdTwvrS5:T2CPpPejyYK7E9ZnJWdTwvW5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Satan also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zbot.244
FireEyeGeneric.mg.0afa321c36913d27
McAfeeGenericRXHA-PQ!0AFA321C3691
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zbot.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056ebdd1 )
BitDefenderGen:Variant.Zbot.244
K7GWTrojan ( 0056ebdd1 )
Cybereasonmalicious.c36913
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Ransomware.Satan-5713061-0
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaRansom:Win32/Nasan.440cb719
NANO-AntivirusTrojan.Win32.Kryptik.gakgsp
RisingRansom.FileCryptor!8.1A7 (CLOUD)
Ad-AwareGen:Variant.Zbot.244
EmsisoftGen:Variant.Zbot.244 (B)
ComodoMalware@#3n3oj7rnyenqw
F-SecureHeuristic.HEUR/AGEN.1102642
ZillyaTrojan.Kryptik.Win32.1746932
TrendMicroRansom_NATAS.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.qh
SophosMal/Generic-R + Mal/Behav-010
IkarusTrojan.Kazy
MaxSecureTrojan.Malware.74553503.susgen
AviraHEUR/AGEN.1102642
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Occamy
MicrosoftTrojan:Win32/Occamy.CC2
ArcabitTrojan.Zbot.244
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Zbot.244
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C1940389
Acronissuspicious
BitDefenderThetaAI:Packer.1844F42C1E
ALYacGen:Variant.Zbot.244
VBA32Trojan.Occamy
MalwarebytesRansom.Satan
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.CSO
TrendMicro-HouseCallRansom_NATAS.SM1
TencentWin32.Trojan.Zbot.Jmo
YandexTrojan.GenAsa!IYKUx0pxsoM
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
FortinetW32/Natas.A!tr.ransom
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/TrojanPSW.Generic.HxQBWIcA

How to remove Ransom.Satan?

Ransom.Satan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment