Ransom

What is “Ransom.TorrentLocker.92 (B)”?

Malware Removal

The Ransom.TorrentLocker.92 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.TorrentLocker.92 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom.TorrentLocker.92 (B)?


File Info:

name: 514C5124F7C16EC0E273.mlw
path: /opt/CAPEv2/storage/binaries/a507220a3151371943c010baaf6b74490f87db51035e0d1e526154e9894883a2
crc32: 6D9B684F
md5: 514c5124f7c16ec0e273cff3bfdb57e7
sha1: de49d53916c9afa76514292eb6bba2d48730f9ee
sha256: a507220a3151371943c010baaf6b74490f87db51035e0d1e526154e9894883a2
sha512: b49c0c11d4ddee47394731b44e6c18b2693e64fc8a21ea0a51cf6d702229d53ddbd8f4637e4b03c1ec3193b920d8c5ecc38116a8d86e86f4d3c2d05c7893d5c2
ssdeep: 3072:RTC7MKza/YY7ESZmU/iq312IuvAVnRvOmzn1aDGrXnrz2UzEJril+T0g0niYlEwv:R+7rEpQUq6yvAddRZrXnuUowl+TNxfg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E364D0E07147066FD67CE2B08CA3E9BFA165D8D2419642A19D7CED0BBB8FC99404371B
sha3_384: b4f48770c75f751035cff90c21a6c17bd173c4074d0dad0cfd243d7e9d10cd6ee289591a547d646db738c424acd22a4a
ep_bytes: 558bec51689c0100006a00ff1524c040
timestamp: 2013-04-11 09:24:16

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Ransom.TorrentLocker.92 (B) also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ransom.TorrentLocker.92
FireEyeGeneric.mg.514c5124f7c16ec0
SkyhighBehavesLike.Win32.PWSZbot.fc
ALYacGen:Variant.Ransom.TorrentLocker.92
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.ShipUp.Win32.1330
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
K7GWTrojan ( 004cf6b81 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Agent.eq
VirITI-WORM.Beagle.DM
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AYMY
APEXMalicious
ClamAVWin.Packed.Mikey-9946640-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.TorrentLocker.92
NANO-AntivirusTrojan.Win32.ShipUp.bqpnlu
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Kryptik.16000289
EmsisoftGen:Variant.Ransom.TorrentLocker.92 (B)
F-SecureTrojan.TR/Gepys.sqwxya
DrWebTrojan.Redirect.140
VIPREGen:Variant.Ransom.TorrentLocker.92
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
SophosTroj/Gyepis-A
IkarusTrojan.Win32.Crypt
JiangminTrojan/Generic.avyfe
VaristW32/Zbot.JC.gen!Eldorado
AviraTR/Gepys.sqwxya
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Ransom.TorrentLocker.92
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.170T050
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ShipUp.R639399
Acronissuspicious
VBA32BScope.Malware-Cryptor.Hlux
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.WebSpoof.Gen.AL
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.AYUW!tr
BitDefenderThetaGen:NN.ZexaF.36802.tO3@ayn@08ic
AVGWin32:Gepys-E [Trj]
Cybereasonmalicious.4f7c16
DeepInstinctMALICIOUS

How to remove Ransom.TorrentLocker.92 (B)?

Ransom.TorrentLocker.92 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment