Ransom

What is “Ransom.Thanatos”?

Malware Removal

The Ransom.Thanatos is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Thanatos virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom.Thanatos?


File Info:

crc32: B8BC8A9B
md5: 48ea3794091a9f17e12f5c1a90e1f7d7
name: 48EA3794091A9F17E12F5C1A90E1F7D7.mlw
sha1: 1bb17eef59764e84f95b7a5c0aad649b8517ee43
sha256: dcd725c415cebc7df170edf49af18d6f86e76ef75185737de5959405f4aecc56
sha512: 0355be6a2b2cf58d4ca5b11de5f84803240587937cd28d064df20ac38c945352e14c78e21006824114f67ede71be3ab27cc27b05759fc23a1fb8dcfa31a7244f
ssdeep: 3072:otcvKR5Kkzk1s6eKSEqlcRHG9fHdJM9F+f:JoFEqlc09fd6U
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Client-kildef2.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Client-kildef2.exe

Ransom.Thanatos also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.MSIL.Basic.6.Gen
FireEyeGeneric.mg.48ea3794091a9f17
McAfeeRansom-Thanos!48EA3794091A
MalwarebytesRansom.Thanatos
AegisLabTrojan.MSIL.Encoder.j!c
BitDefenderTrojan.MSIL.Basic.6.Gen
K7GWTrojan ( 005690201 )
Cybereasonmalicious.4091a9
BitDefenderThetaGen:NN.ZemsilF.34780.gm0@a8pnc4l
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.gen
AlibabaTrojan:MSIL/Filecoder.dd9a5a13
Ad-AwareTrojan.MSIL.Basic.6.Gen
SophosMal/Generic-S
DrWebTrojan.Encoder.33405
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.MSIL.Basic.6.Gen (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Encoder.gen
GDataTrojan.MSIL.Basic.6.Gen
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4295463
ALYacTrojan.MSIL.Basic.6.Gen
ESET-NOD32a variant of MSIL/Filecoder.Thanos.A
TencentMsil.Trojan.Encoder.Pgdm
MAXmalware (ai score=89)
eGambitUnsafe.AI_Score_96%
FortinetMSIL/Thanos.A!tr.ransom
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Trojan.Ransom.d23

How to remove Ransom.Thanatos?

Ransom.Thanatos removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment