Ransom

Ransom.Scarab.42 removal tips

Malware Removal

The Ransom.Scarab.42 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Scarab.42 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Scarab.42?


File Info:

crc32: CB3EC503
md5: 4ae16545dd091b802b7eb8a47bed8506
name: 4AE16545DD091B802B7EB8A47BED8506.mlw
sha1: 40934b22cb1ed88b9c26f4732c3d11643c8d8960
sha256: b94ec4d127a95c98bf1dffbf2b1a3f203533b1c494dc56bddefbfe83fc8215ab
sha512: 68463fc86dea5d935c0964458e7cee96c866d10dee65acd409248a853084e657a94310f717a82174eed43528f367bc9847e11cb149d44fa3c20a501f4b6de016
ssdeep: 24576:hVPBNMlSsJ0HjBZ5cN8elCHP5UGIQ6e5lB+BsG:/B2lSxjhGBwP5UlQ6Mlys
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2007-2015
InternalName: Cares
FileVersion: 7.4.81.3
CompanyName: PassMark Software
FileDescription: Substring 256bit Task
LegalTrademarks: (C) 2007-2015
Comments: Substring 256bit Task
ProductName: Cares
ProductVersion: 7.4.81.3
PrivateBuild: 7.4.81.3
OriginalFilename: Cares.exe
Translation: 0x0409 0x04b0

Ransom.Scarab.42 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052daff1 )
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.56068
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Scarab.42
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.69640
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Yakes.34c9c36c
K7GWTrojan ( 0052daff1 )
Cybereasonmalicious.5dd091
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packer.MalwareCrypter-6620810-1
KasperskyTrojan.Win32.Yakes.wvjq
BitDefenderGen:Variant.Ransom.Scarab.42
NANO-AntivirusTrojan.Win32.Yakes.fiacpj
MicroWorld-eScanGen:Variant.Ransom.Scarab.42
TencentMalware.Win32.Gencirc.114cfa4d
Ad-AwareGen:Variant.Ransom.Scarab.42
SophosMal/Generic-S
ComodoMalware@#m72hses0xiwv
BitDefenderThetaGen:NN.ZexaF.34796.nr3@aKy!vqmi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansom-O.e
FireEyeGeneric.mg.4ae16545dd091b80
EmsisoftGen:Variant.Ransom.Scarab.42 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.adzt
AviraTR/FileCoder.biysb
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ransom.Scarab.42
GDataGen:Variant.Ransom.Scarab.42
McAfeeArtemis!4AE16545DD09
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Azorult
MalwarebytesMalware.AI.1901226744
PandaTrj/GdSda.A
YandexTrojan.Yakes!rYi0QZagi6k
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Yakes.WVJQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Botnet.Yakes.HgIASS0A

How to remove Ransom.Scarab.42?

Ransom.Scarab.42 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment