Ransom

How to remove “Ransom.Sigmal.S4021875”?

Malware Removal

The Ransom.Sigmal.S4021875 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Sigmal.S4021875 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

How to determine Ransom.Sigmal.S4021875?


File Info:

crc32: F59D5AC7
md5: 669bfe568428e02ed4369f9c33a2b610
name: 669BFE568428E02ED4369F9C33A2B610.mlw
sha1: 516b2d915a044067a876613b88156f6fbbfb7bb7
sha256: 8808fcd5860f8a1c6e84a0061761e56f87aa8ba21283a3a1d2b78e748b629b4c
sha512: a9bf3237723b3a069bbde528f3847e516670c492f5a81abdcef37ca5b23b47ee6e933c6368d2382e7fcf715bf3ef2392cea5e3b839b380b5ff9834b77f407ab0
ssdeep: 3072:ygM7Fnxr9SB+TXh/sEhD4yfdNxlq5JcWxxxxxxxN5FtUZiAl5UFoN+:sxr9Sg/s2+2WxxxxxxxN5FtUZNl5a
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: ransom.Scr
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: ransom.Scr

Ransom.Sigmal.S4021875 also known as:

K7AntiVirusTrojan ( 0051c2441 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.26652
CynetMalicious (score: 99)
CAT-QuickHealRansom.Sigmal.S4021875
ALYacGen:Variant.MSIL.Bladabindi.6
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0051c2441 )
Cybereasonmalicious.68428e
BaiduMSIL.Trojan-Dropper.Binder.a
CyrenW32/MSIL_Binder.A.gen!Eldorado
SymantecRansom.Petya
ESET-NOD32a variant of MSIL/TrojanDropper.Binder.CA
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Petya-6992434-0
KasperskyTrojan-Ransom.Win32.Petr.aqv
BitDefenderGen:Variant.MSIL.Bladabindi.6
NANO-AntivirusTrojan.Win32.Agent.dzsrep
MicroWorld-eScanGen:Variant.MSIL.Bladabindi.6
Ad-AwareGen:Variant.MSIL.Bladabindi.6
SophosTroj/dnsauce-B
ComodoTrojWare.MSIL.TrojanDropper.Binder.CA@7nerge
BitDefenderThetaGen:NN.ZemsilF.34796.rm0@aSY5b8o
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_BINDER.SMA
McAfee-GW-EditionBackDoor-FBHS!669BFE568428
FireEyeGeneric.mg.669bfe568428e02e
EmsisoftGen:Variant.MSIL.Bladabindi.6 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bcpht
AviraBDS/Bladabindi.alif
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.MSIL.Bladabindi.6
AhnLab-V3Malware/Win32.Generic.C551599
McAfeeBackDoor-FBHS!669BFE568428
MAXmalware (ai score=82)
VBA32TrojanRansom.Petr
MalwarebytesBackdoor.Bladabindi
TrendMicro-HouseCallTROJ_BINDER.SMA
RisingRansom.Destructor!1.B060 (CLASSIC)
IkarusTrojan-Dropper.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Dropper_Binder.BS!tr
AVGWin32:RansomX-gen [Ransom]
Qihoo-360HEUR/QVM03.0.AF76.Malware.Gen

How to remove Ransom.Sigmal.S4021875?

Ransom.Sigmal.S4021875 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment