Ransom

Ransom:MSIL/SamSam.D!dr removal instruction

Malware Removal

The Ransom:MSIL/SamSam.D!dr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/SamSam.D!dr virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:MSIL/SamSam.D!dr?


File Info:

crc32: 375ABC55
md5: 6e3903e362da159b9a8e521672d65a64
name: 6E3903E362DA159B9A8E521672D65A64.mlw
sha1: 1ada3508d539a81633c366cf3bd3b3ba9ee378cd
sha256: 4e3d2b76397967d7c061e8fc3cae2335dbbef7ae72a8288c33fc112ed9b14bf8
sha512: 09c21752cbfe4851937ed14c7950059a4c9399dc722fed1eb2359c00c890e92021f0bdda9a3ac5d408a88f12472eb6246a1c241d05b52a4d584ed5cbc1d80540
ssdeep: 96:5tP02tT/3kHmCe6nmRaSLqzKCQzRYeKkNGJi/5o+TRzNt:5NvtYH4SmRxJCoRYCNVhF3
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: gsdrgb sdrgrhsdgb sd u
Assembly Version: 7.6.4.3
InternalName: sbjfycvsegfksj.exe
FileVersion: 1.2.1.7
CompanyName: kuh dkuhgku sdhgiuyqiurtajdsfhf ajhsf kui
LegalTrademarks: is8 dyg gvsytgfka efit jgdf gfuj age
Comments: khdk gsdkughk ishdgkish dgkuhdku
ProductName: ku esytoisy jgsdfjb gskufh buftiu
ProductVersion: 1.2.1.7
FileDescription: ks dhk sdhkjg dkgkshdgkhdkg skjfdhk
OriginalFilename: sbjfycvsegfksj.exe

Ransom:MSIL/SamSam.D!dr also known as:

MicroWorld-eScanGen:Variant.Ransom.Samas.13
FireEyeGen:Variant.Ransom.Samas.13
Qihoo-360Win32/Virus.326
McAfeeRansomware-GJI!6E3903E362DA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051acfe1 )
BitDefenderGen:Variant.Ransom.Samas.13
K7GWTrojan ( 0051acfe1 )
Cybereasonmalicious.362da1
BitDefenderThetaGen:NN.ZemsilF.34590.am0@a4ad0rp
CyrenW32/SamSam.A.gen!Eldorado
SymantecTrojan.Gen.2
AvastWin32:Malware-gen
ClamAVWin.Packer.Agent-6403417-1
NANO-AntivirusTrojan.Win32.Runner.evgtsk
RisingRansom.SamSam!8.F306 (CLOUD)
Ad-AwareGen:Variant.Ransom.Samas.13
EmsisoftTrojan.Runner (A)
ComodoApplicUnwnt@#3jtm47xvi8hl5
F-SecurePotentialRisk.PUA/DomaIQ.Gen
ZillyaTrojan.Runner.Win32.850
TrendMicroTrojan.MSIL.SAMRUN.SMFG
McAfee-GW-EditionRansomware-GJI!6E3903E362DA
SophosMal/Generic-R + Troj/Ransom-EVF
IkarusTrojan.MSIL.Runner
AviraPUA/DomaIQ.Gen
MicrosoftRansom:MSIL/SamSam.D!dr
ArcabitTrojan.Ransom.Samas.13
GDataGen:Variant.Ransom.Samas.13
CynetMalicious (score: 85)
ALYacTrojan.MSIL.Runner
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Runner.D
TrendMicro-HouseCallTrojan.MSIL.SAMRUN.SMFG
TencentWin32.Trojan.Domaiq.Wqdl
YandexTrojan.Runner!5/fOY1Fhwrs
FortinetMSIL/Kryptik.HSF!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:MSIL/SamSam.D!dr?

Ransom:MSIL/SamSam.D!dr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment