Ransom

What is “Ransom.VenusLocker”?

Malware Removal

The Ransom.VenusLocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.VenusLocker virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.VenusLocker?


File Info:

name: F5E72BF445387EDDEC00.mlw
path: /opt/CAPEv2/storage/binaries/2e2cef71bf99594b54e00d459480e1932e0230fb1cbee24700fbc2f5f631bf12
crc32: 756BC476
md5: f5e72bf445387eddec000e0238adf873
sha1: 895eb3047e7a28ce219fdd7e7ad5ce2a61312d93
sha256: 2e2cef71bf99594b54e00d459480e1932e0230fb1cbee24700fbc2f5f631bf12
sha512: d8667ebb53c14e2401b1fd805e4835dedddb3a5dadf75e097ca9fa3047009dfda96b60d82b17fd014e35a0f6a9ca2c294bbf21ee4a5fecf58029d80c5787fcc3
ssdeep: 6144:nRqMJmXIQwAPFoXJDc7V50DErD5xgTw7ozFz254W:nRq6eIQwAuDnDkGcoxfW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A34BE10EAC290F2DC9B4FB995FA59FE50356E308735E3F7DB958EA485326C2C134262
sha3_384: 154fac012f94790da26ed979fb592e1652c66a6dcb022311cc8f1ad3b14093a559c3f32e31a7d0a6945caa3b59831b23
ep_bytes: 558bec681c0100006860af4300e87ec9
timestamp: 2022-07-30 17:23:46

Version Info:

0: [No Data]

Ransom.VenusLocker also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Ransom.RTH.1
FireEyeGeneric.mg.f5e72bf445387edd
CAT-QuickHealRansom.Venus.S28803801
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.25511
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00564d931 )
AlibabaRansom:Win32/Filecoder.163b9fe5
K7GWTrojan ( 00564d931 )
Cybereasonmalicious.445387
VirITTrojan.Win32.Genus.LYR
CyrenW32/Filecoder.DT.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.OBQ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Heur.Ransom.RTH.1
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:RansomX-gen [Ransom]
TencentWin32.Trojan.Filecoder.Vwhl
Ad-AwareGen:Heur.Ransom.RTH.1
EmsisoftGen:Heur.Ransom.RTH.1 (B)
ComodoMalware@#1q1ueeajgi0dw
DrWebTrojan.Encoder.33303
VIPREGen:Heur.Ransom.RTH.1
TrendMicroRansom.Win32.VENUS.THHOHBB
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.high.ml.score
SophosMal/Generic-S + Mal/Emogen-Y
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Ransom.RTH.1
JiangminTrojan.Generic.hmtxt
WebrootW32.Ransom.Venus
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Filecoder
KingsoftWin32.Troj.Generic.jm.(kcloud)
ArcabitTrojan.Ransom.RTH.1
MicrosoftRansom:Win32/Filecoder!MSR
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5220541
McAfeeRDN/Ransom
MAXmalware (ai score=87)
VBA32BScope.TrojanRansom.Venus
MalwarebytesRansom.VenusLocker
TrendMicro-HouseCallRansom.Win32.VENUS.THHOHBB
RisingRansom.Agent!8.6B7 (TFE:3:kEw9647254Q)
IkarusTrojan-Ransom.Venus
FortinetW32/Filecoder.OBQ!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34754.ouW@aKmr5Tii
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.VenusLocker?

Ransom.VenusLocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment