Ransom

Ransom.TripleM information

Malware Removal

The Ransom.TripleM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.TripleM virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom.TripleM?


File Info:

crc32: 3622C4A8
md5: 2bc57203017a4e87ad1ea7a2ddd3b552
name: 2BC57203017A4E87AD1EA7A2DDD3B552.mlw
sha1: 4c80db854e951c0758306d3e57fe48aa48d37d63
sha256: e16e54cb922d7b17892d41980efa6718b963b57328a1eacf9a35edf01e587ba7
sha512: 9a136840035b832bec2cca5c2616254cedc93f2caab0b4a142d5260a906d4cf7c9d183a85be1b1cc76925624074b0f43dc112b4a08ea04430d3b0f60c49b4535
ssdeep: 768:jQyeOMPP+YZiO/oL6rbhykTwml2WGi1kdZj2:j03+Yflrbh552PlTq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 ARMY.MIL 2019
Assembly Version: 2.0.1.9
InternalName: DropShit.exe
FileVersion: 2.0.1.9
CompanyName: StopBussiness
LegalTrademarks: xa9 ARMY.MIL 2019
Comments: StopBussiness
ProductName: StopBussiness
ProductVersion: 2.0.1.9
FileDescription: StopBussiness
OriginalFilename: DropShit.exe

Ransom.TripleM also known as:

K7AntiVirusTrojan ( 005508b71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.56458
CynetMalicious (score: 99)
McAfeeRansomware-GPM!2BC57203017A
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.14876
SangforRansom.MSIL.TRIPLEM.DA
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:MSIL/FileCryptor.930b8bfc
K7GWTrojan ( 005508b71 )
Cybereasonmalicious.3017a4
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.RY
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.gen
BitDefenderGen:Variant.Ursu.527610
NANO-AntivirusTrojan.Win32.Ransom.hnqwom
MicroWorld-eScanGen:Variant.Ursu.527610
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Ursu.527610
SophosMal/Generic-R + Mal/TripM-B
ComodoMalware@#tj7rh1vuuw3m
F-SecureTrojan.TR/Ransom.nsaqa
BitDefenderThetaAI:Packer.7D7F2F961F
TrendMicroRansom.MSIL.TRIPLEM.SM
McAfee-GW-EditionRansomware-GPM!2BC57203017A
FireEyeGeneric.mg.2bc57203017a4e87
EmsisoftGen:Variant.Ursu.527610 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Ransom.nsaqa
Antiy-AVLTrojan/Generic.ASMalwS.3094F19
MicrosoftRansom:MSIL/DelShad.DA!MTB
ArcabitTrojan.Ursu.D80CFA
AegisLabTrojan.MSIL.Encoder.j!c
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Encoder.gen
GDataGen:Variant.Ursu.527610
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=82)
MalwarebytesRansom.TripleM
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.MSIL.TRIPLEM.SM
RisingRansom.Reborn!1.B6B6 (CLASSIC)
YandexTrojan.Filecoder!DX95DI5KkN8
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.73702460.susgen
FortinetMSIL/Filecoder.RY!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.TripleM?

Ransom.TripleM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment