Ransom

Ransom.TorrentLocker.92 removal guide

Malware Removal

The Ransom.TorrentLocker.92 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.TorrentLocker.92 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom.TorrentLocker.92?


File Info:

name: 46A869E747D42D107BE1.mlw
path: /opt/CAPEv2/storage/binaries/846c585eed537e172c47b45507e3bce84c62111cf6b37e8788fbafe5a17fa485
crc32: 62C7DA16
md5: 46a869e747d42d107be1a81caabc64c1
sha1: e262278d529105f4e7f5b755078abf678286c8d4
sha256: 846c585eed537e172c47b45507e3bce84c62111cf6b37e8788fbafe5a17fa485
sha512: 8c931bf2c3bbccae040139e57c95bfe47d3e9dc341e7b8a8a5a47b7ce3e82fc55bb4a3635db9269fa486a5dfdde865c1ba48b6993715d1a222d8e0b2c5acebcd
ssdeep: 3072:N6yOaBa13l0TX7kOLaAWU22EkrXouzVwOwfWx5ZIAKCbZ9gKb:n/YsTrGm22EkrRzVXYu57KCb3gKb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA849C46F49B4D07D9520CF1847419BE8259EFAA3F27FE331886FC4ED61ABA8381516C
sha3_384: 221a348286f83d181d46d53fae1a8d6a1b12517ace5f77916a87c4bcbc7ce02f81544ffb4550504038ba1bafdb67d100
ep_bytes: 558bec515505413c000005413c000005
timestamp: 2013-04-05 15:37:12

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Ransom.TorrentLocker.92 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Gepys.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.TorrentLocker.92
FireEyeGeneric.mg.46a869e747d42d10
CAT-QuickHealTjnDroppr.Gepys.S85760
SkyhighBehavesLike.Win32.PWSZbot.ft
ALYacGen:Variant.Ransom.TorrentLocker.92
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4652932
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
AlibabaTrojan:Win32/Kryptik.e124
K7GWTrojan ( 004cf6b81 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Ransom.TorrentLocker.92
BitDefenderThetaGen:NN.ZexaF.36802.y01@aKmj6Aec
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYEN
APEXMalicious
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
ClamAVWin.Trojan.Redirect-6055402-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.TorrentLocker.92
NANO-AntivirusVirus.Win32.Sality.bgiylc
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Kryptik.16000652
EmsisoftGen:Variant.Ransom.TorrentLocker.92 (B)
BaiduWin32.Trojan.Agent.eq
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Redirect.140
VIPREGen:Variant.Ransom.TorrentLocker.92
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
SophosMal/EncPk-AIT
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=87)
JiangminTrojan/ShipUp.jb
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Zbot.JC.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
MicrosoftTrojan:Win32/ShipUp!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1UAV3XA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5592235
Acronissuspicious
McAfeePWS-Zbot.gen.xs
VBA32Malware-Cryptor.Cidox.9413
Cylanceunsafe
PandaTrj/Hexas.HEU
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!KyfvK6+Qan4
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYGJ!tr
AVGWin32:Gepys-E [Trj]
Cybereasonmalicious.747d42
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/ShipUp

How to remove Ransom.TorrentLocker.92?

Ransom.TorrentLocker.92 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment