Ransom

Ransom:MSIL/Godcrypt removal tips

Malware Removal

The Ransom:MSIL/Godcrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/Godcrypt virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ransom:MSIL/Godcrypt?


File Info:

crc32: 0AEDB2C8
md5: 11c4b543fdad2bfbfd9fc4a5324d5fac
name: 11C4B543FDAD2BFBFD9FC4A5324D5FAC.mlw
sha1: 199ace65a9b4f7866d22a7a6e878be6ec2d8cb47
sha256: cfc54a03b5261e3569e6c5692bae3398bb97e600dffb9889ea0a0ea246d587df
sha512: 0ee08546a406cbb77b3f0a59ad7c552589d2e96992edd6d0f5a0cc752a4ae86ec078b670faf1c7c7ac25cfa8f04d9da8400ccfca1e99e785cba203be883ad097
ssdeep: 12288:mIdEoEZdE/dE/dE/dE79z3iO6NxnmTadEhteJ+ot2f+15e0id2HqrH8888s8888:mj3k666I7mRhtqWuE2K78888s88886
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright Godsomware xa9 2017 - 2018 All Reverved
Assembly Version: 1.0.0.0
InternalName: Godsomware.exe
FileVersion: 1.0.0.0
CompanyName: NinjaGhost
LegalTrademarks: Ninja
Comments: Ransomware God Crypt v1.0 by NinjaGhost
ProductName: Godsomware v1.0
ProductVersion: 1.0.0.0
FileDescription: God Crypt v1.0
OriginalFilename: Godsomware.exe

Ransom:MSIL/Godcrypt also known as:

K7AntiVirusTrojan ( 0053e3bb1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.Ransom.ScreenLocker
CylanceUnsafe
ZillyaTrojan.Wanna.Win32.520
AlibabaRansom:MSIL/Wanna.3d953153
K7GWTrojan ( 0053e3bb1 )
Cybereasonmalicious.3fdad2
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Hoax.FakeFilecoder.DH
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Wanna.gen
BitDefenderGeneric.Ransom.GodLock.CE18538A
NANO-AntivirusTrojan.Win32.Ransom.firyuk
MicroWorld-eScanGeneric.Ransom.GodLock.CE18538A
TencentMsil.Risk.Hoax.Dxwu
Ad-AwareGeneric.Ransom.GodLock.CE18538A
SophosMal/Generic-S
ComodoMalware@#1nzkns82xrjac
BitDefenderThetaGen:NN.ZemsilF.34126.Ln0@a0rmp2n
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXMU-BH!11C4B543FDAD
FireEyeGeneric.Ransom.GodLock.CE18538A
EmsisoftGeneric.Ransom.GodLock.CE18538A (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.MSIL.kmhd
AviraTR/FakeWanna.nhrqr
MicrosoftRansom:MSIL/Godcrypt
ArcabitGeneric.Ransom.GodLock.CED486AA
ZoneAlarmHoax.MSIL.FakeRansom.gen
GDataGeneric.Ransom.GodLock.CE18538A
AhnLab-V3Trojan/Win32.Ransom.C2898804
McAfeeGenericRXMU-BH!11C4B543FDAD
MAXmalware (ai score=94)
VBA32TrojanRansom.MSIL.Wanna
PandaTrj/GdSda.A
YandexHoax.FakeFilecoder!Q3EMjynJ+B0
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/FakeFilecoder.DH!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:MSIL/Godcrypt?

Ransom:MSIL/Godcrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment