Ransom

Ransom.TorrentLocker.Generic malicious file

Malware Removal

The Ransom.TorrentLocker.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.TorrentLocker.Generic virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Hungarian
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • A system process is generating network traffic likely as a result of process injection
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
gdihlpojej.bpstaxapn.com
aquwo.bpstaxapn.com
ihofr.bpstaxapn.com
fgypyxjluv.bpstaxapn.com
ubityvu.bpstaxapn.com
avikil.bpstaxapn.com
iryxiz.bpstaxapn.com
yfare.bpstaxapn.com
igysi.bpstaxapn.com
rnenajiz.bpstaxapn.com
gtutyne.bpstaxapn.com
ipydsti.bpstaxapn.com
evacycivo.bpstaxapn.com
onusafolad.bpstaxapn.com
ysoxinixe.bpstaxapn.com
iqykyjexehe.bpstaxapn.com
ybinizib.bpstaxapn.com
exip.bpstaxapn.com

How to determine Ransom.TorrentLocker.Generic?


File Info:

crc32: 69B87A77
md5: b7977e2420d95dd94f2ab078d0606be1
name: B7977E2420D95DD94F2AB078D0606BE1.mlw
sha1: 69461582a8373b065053991571107c46346b9102
sha256: 61e27a9394527a119c9a6c7934c3900c09612998893293918171721d74363c7f
sha512: 865de907e74f015124d11515eaa5553298e18ca920549d44f2659aaabc7fc665f03501ec708b0bfd0bfed62e16337395073829161a831b4b155ff50472f6270e
ssdeep: 12288:5Y20Fdx6hTnyHIn8UDLJ/4nbOcW58i1TUC+9CTz4byYU1XsUPhf:fn8w4nbOcviyC+kTz4rU11P
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileDescription: Frostbitten Duchies Curiosity
CompanyName: Abu Mami

Ransom.TorrentLocker.Generic also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.2685
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.24
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.128947
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Teerac.d333c918
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.420d95
BaiduWin32.Trojan.Kryptik.qb
SymantecTrojan.Gen.2
ESET-NOD32Win32/Filecoder.TorrentLocker.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.24
NANO-AntivirusTrojan.Win32.Androm.dyhzdk
MicroWorld-eScanGen:Heur.Mint.Zard.24
TencentWin32.Trojan.Generic.Pgmp
Ad-AwareGen:Heur.Mint.Zard.24
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34058.Sq0@aSRRmvmO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRILOCK.SMB
McAfee-GW-EditionRansom-Teerac!B7977E2420D9
FireEyeGeneric.mg.b7977e2420d95dd9
EmsisoftGen:Heur.Mint.Zard.24 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.bad
WebrootW32.Trojan.TeslaCrypt.Gen
AviraHEUR/AGEN.1108347
Antiy-AVLTrojan/Generic.ASMalwS.154D186
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Teerac.A
ArcabitTrojan.Mint.Zard.24
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Mint.Zard.24
AhnLab-V3Win-Trojan/Teerac.Gen
McAfeeRansom-Teerac!B7977E2420D9
MAXmalware (ai score=80)
VBA32Backdoor.Androm
MalwarebytesRansom.TorrentLocker.Generic
PandaGeneric Suspicious
TrendMicro-HouseCallRansom_CRILOCK.SMB
RisingTrojan.Generic@ML.90 (RDML:w2iN7lFMDRY9KIftl+QWbw)
IkarusTrojan.Win32.Filecoder
FortinetW32/Injector.CRIZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.TorrentLocker.HwcBEpsA

How to remove Ransom.TorrentLocker.Generic?

Ransom.TorrentLocker.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment