Ransom

Ransom.Xorist (file analysis)

Malware Removal

The Ransom.Xorist is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Xorist virus can do?

  • The executable is compressed using UPX
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Xorist?


File Info:

crc32: F0EFA4E2
md5: 9f00b078772107678e24057aa90f1d46
name: 9F00B078772107678E24057AA90F1D46.mlw
sha1: 9a50b0c72344f5d795a3fba4437085a128f5472d
sha256: 8546151cce464c8a5b241bc6d1f62e26942cbec8e605e3dc55f7d79a1302618b
sha512: 82e597207f98bd73d5834dc8d756f1ae326bf87e9dfb0994340f68a4ebfc5b9d66920e9c2e99377f2c56ee72d98dd59c5fd305e6725aba66f1f2542651e5bd67
ssdeep: 1536:oPOUQrZ0FvzAjRdsmewYmKYPwBtn3XxW2GAW/RLCG90+OlHgjU8:rUQi0tdsmewYsPoFXwKKRLCGFOSjU8
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom.Xorist also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.AIG
CAT-QuickHealTrojan.Ransom.FO4
ALYacTrojan.Ransom.Xorist
CylanceUnsafe
VIPRETrojan.Win32.Ransom.fo (v)
AegisLabTrojan.Win32.Xorist.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005451b81 )
BitDefenderTrojan.Ransom.AIG
K7GWTrojan ( 005451b81 )
Cybereasonmalicious.877210
BaiduWin32.Trojan.Filecoder.g
CyrenW32/Filecoder.Y.gen!Eldorado
SymantecRansom.CryptoTorLocker
TotalDefenseWin32/Ransom.A!generic
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.CryptoTorLocker2015-1
KasperskyTrojan-Ransom.Win32.Xorist.ln
AlibabaRansom:Win32/Xorist.9f8484c5
NANO-AntivirusTrojan.Win32.Xorist.dxuuhl
ViRobotTrojan.Win32.A.Xorist.1268736[UPX]
TencentTrojan.Win32.CryptoTorLocker2015.a
Ad-AwareTrojan.Ransom.AIG
EmsisoftTrojan.Ransom.AIG (B)
ComodoTrojWare.Win32.Kryptik.ER@4o1ar2
F-SecureTrojan.TR/Ransom.Xorist.EJ
DrWebTrojan.Encoder.94
ZillyaTrojan.Ransom.Win32.926
TrendMicroRansom_XORIST.SMA
McAfee-GW-EditionBehavesLike.Win32.Pluto.cm
MaxSecureTrojan.Malware.121218.susgen
FireEyeGeneric.mg.9f00b07877210767
SophosMal/Generic-R + Troj/Ransom-EY
IkarusTrojan-Ransom.Xorist
JiangminTrojan/Xorist.js
WebrootW32.Ransom
AviraTR/Ransom.Xorist.EJ
Antiy-AVLTrojan[Ransom]/Win32.Xorist
MicrosoftRansom:Win32/Sorikrypt
ArcabitTrojan.Ransom.AIG
ZoneAlarmTrojan-Ransom.Win32.Xorist.ln
GDataWin32.Trojan-Ransom.Xorist.D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xorist.R25524
McAfeeGenericRXAA-AA!9F00B0787721
MAXmalware (ai score=99)
VBA32Hoax.Xorist
MalwarebytesRansom.Xorist
PandaTrj/RansomXor.A
ESET-NOD32Win32/Filecoder.Q
TrendMicro-HouseCallRansom_XORIST.SMA
RisingRansom.Sorikrypt!8.8822 (CLOUD)
YandexTrojan.GenAsa!/o0pq2Faa4I
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Xorist.DD8C!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34590.gmGfa0Yvkcii
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Xorist.HgIASOQA

How to remove Ransom.Xorist?

Ransom.Xorist removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment