Ransom

Ransom.Zlocker information

Malware Removal

The Ransom.Zlocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Zlocker virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Ransom.Zlocker?


File Info:

crc32: 6D69C137
md5: 2bed58f3852e80f55b1e3f72eb30d9f4
name: 2BED58F3852E80F55B1E3F72EB30D9F4.mlw
sha1: f8e39156ed0e4e065328edbc337844bb92e80e6e
sha256: 40807f5b8321694150abfb543a6b1e958c4a352004b57030afacb2d4116cc6e5
sha512: 28dcc6e73dc38ed788cef059f6db3ea12b3e8631be7a448a83ddea4ce337a59400e3ecfdd60c4be8ac30b88d5789fe91607f70f5c4c8bc66b071261d9ea6784e
ssdeep: 768:6eWS8oCa9Q2Ai+vwHXCMqwU1DqBKfeI0NI:6eWJoCa9QA+vOXje1DqBg9d
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: qwe.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: qwe
ProductVersion: 1.0.0.0
FileDescription: qwe
OriginalFilename: qwe.exe

Ransom.Zlocker also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.217938
McAfeeArtemis!2BED58F3852E
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d443e1 )
BitDefenderGen:Variant.MSILPerseus.217938
K7GWTrojan ( 004d443e1 )
Cybereasonmalicious.3852e8
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.Win32.Generic
AlibabaTrojan:MSIL/Filecoder.643a5d77
NANO-AntivirusTrojan.Win32.Encoder.imzyzn
RisingTrojan.Filecoder!8.68 (CLOUD)
Ad-AwareGen:Variant.MSILPerseus.217938
EmsisoftGen:Variant.MSILPerseus.217938 (B)
ComodoMalware@#2y2hjhlp87ufn
F-SecureHeuristic.HEUR/AGEN.1101075
DrWebTrojan.Encoder.3480
ZillyaTrojan.Filecoder.Win32.13791
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.2bed58f3852e80f5
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.MSIL.onbn
MaxSecureTrojan.Malware.74133646.susgen
AviraHEUR/AGEN.1101075
MAXmalware (ai score=87)
Antiy-AVLTrojan/MSIL.DelShad
MicrosoftTrojan:Win32/Occamy.C40
ArcabitTrojan.MSILPerseus.D35352
AegisLabTrojan.MSIL.DelShad.4!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Variant.MSILPerseus.217938
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.FileCoder.R346097
BitDefenderThetaGen:NN.ZemsilF.34590.bm0@aGxOHOp
ALYacTrojan.Ransom.Filecoder
VBA32TScope.Trojan.MSIL
MalwarebytesRansom.Zlocker
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Filecoder.AC
TencentMsil.Trojan.Delshad.Hvjx
YandexTrojan.Filecoder!F0W9RxCmL9U
IkarusTrojan.MSIL.Filecoder
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Filecoder.AC!tr
WebrootW32.Trojan.MSIL.DelShad
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Generic/Trojan.f5a

How to remove Ransom.Zlocker?

Ransom.Zlocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment