Ransom

About “Ransom:MSIL/Reyptson.A” infection

Malware Removal

The Ransom:MSIL/Reyptson.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/Reyptson.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Ransom:MSIL/Reyptson.A?


File Info:

crc32: CAA4EBC3
md5: 3778eb655c766289499ab37f53c42226
name: 3778EB655C766289499AB37F53C42226.mlw
sha1: aaae40f60a6c1b7886d6cdc2d37257473816cb62
sha256: d6b186be27356c6be58614aef060e164ddb52548f437fd0e4d1250d979865eb4
sha512: 4a284b5f3bd1936a1c1e8bc0c02cc9335b9625b4d8be016132a840efbc08b9f86dc22e8fbae88ccb3a4a043eb22e6f763fc4783a949e03d950dcd0ca66645325
ssdeep: 768:zVrHqhRStWSOBmXbc5+jio/B7yhYC7fxwmJRJLoGxa9tQV2mo5C9XgjPILYXOUY:h+S4jBmXbc5++o1yhRHw9wyyqdf/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Ransom:MSIL/Reyptson.A also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.32243
McAfeeRansomware-GCU!3778EB655C76
CylanceUnsafe
ZillyaTrojan.Mucc.Win32.773
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Reyptson.ali1020008
K7GWTrojan ( 700000121 )
Cybereasonmalicious.55c766
SymantecRansom.Reyptson
ESET-NOD32a variant of MSIL/Filecoder.IQ
ZonerTrojan.Win32.60570
APEXMalicious
AvastWin32:Reyptson-A [Trj]
ClamAVWin.Trojan.Reyptson-6367715-0
KasperskyTrojan.Win32.Mucc.bda
BitDefenderTrojan.Ransom.HiddenTear.K
NANO-AntivirusTrojan.Win32.Mucc.esfqmb
MicroWorld-eScanTrojan.Ransom.HiddenTear.K
TencentWin32.Trojan.Mucc.Lkea
Ad-AwareTrojan.Ransom.HiddenTear.K
SophosMal/Generic-R + Mal/Cryptear-E
ComodoMalware@#9clqeedmhc26
BitDefenderThetaGen:NN.ZemsilF.34628.dmW@aG05gxh
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103C320
McAfee-GW-EditionBehavesLike.Win32.Generic.qt
FireEyeGeneric.mg.3778eb655c766289
EmsisoftTrojan.Ransom.HiddenTear.K (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ckndk
MicrosoftRansom:MSIL/Reyptson.A
ArcabitTrojan.Ransom.HiddenTear.K
ZoneAlarmTrojan.Win32.Mucc.bda
GDataMSIL.Email-Worm.Reyptson.A
AhnLab-V3Trojan/Win32.Filecoder.C2318509
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=100)
MalwarebytesRansom.Reyptson
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103C320
RisingRansom.Reyptson!8.EA79 (CLOUD)
YandexTrojan.Mucc!PoNqZiBCSOc
IkarusTrojan.MSIL.Filecoder
FortinetMSIL/Filecoder.IQ!tr.ransom
AVGWin32:Reyptson-A [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Mucc.HwMAjAMB

How to remove Ransom:MSIL/Reyptson.A?

Ransom:MSIL/Reyptson.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment