Ransom

Ransom:MSIL/VenusLocker.A malicious file

Malware Removal

The Ransom:MSIL/VenusLocker.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/VenusLocker.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Ransom:MSIL/VenusLocker.A?


File Info:

crc32: 0EEEFC2F
md5: 20e741dfd69f58db162377bcc355e3f9
name: 20E741DFD69F58DB162377BCC355E3F9.mlw
sha1: b5d01f55f02159c4ffaa5f0a1868ecf39571d6e3
sha256: b2dbd94c62aa3a204f401b9f9522eddcb1a60bf76d6b83ce1b6299fa097e7c83
sha512: 31b828fb1bb402de4482a43c8c15e2c82c91909aea50d0b04c40dd401806ee3cd08c09aca4a974d8d152f6be8c29a56a73e23283a3574123584279949ade0e9c
ssdeep: 12288:OVFNyLxXcP/bBwW4l4xSMz47ao0Hu46h7y:OVzZeWnxSE4Ooj7y
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: VenusLocker.exe
FileVersion: 1.0.0.0
ProductName: VenusLocker
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: VenusLocker.exe

Ransom:MSIL/VenusLocker.A also known as:

K7AntiVirusTrojan ( 004f65aa1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5193
CynetMalicious (score: 85)
ALYacTrojan.Dropper.1003362
CylanceUnsafe
SangforRansom.MSIL.VenusLocker.A
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004f65aa1 )
Cybereasonmalicious.fd69f5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.CE
APEXMalicious
AvastMSIL:Ransom-S [Trj]
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGeneric.Ransom.Hiddentear.A.3E1D9874
NANO-AntivirusTrojan.Win32.Encoder.eooluq
ViRobotTrojan.Win32.VenusLocker.Gen.A
MicroWorld-eScanGeneric.Ransom.Hiddentear.A.3E1D9874
TencentMalware.Win32.Gencirc.10bce706
Ad-AwareGeneric.Ransom.Hiddentear.A.3E1D9874
SophosMal/VenusLk-A
ComodoMalware@#1s6x9r1kx93al
BitDefenderThetaGen:NN.ZemsilF.34628.Bm1@aWlVple
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_VENUSLOCK.SM
McAfee-GW-EditionGenericRXBJ-PZ!20E741DFD69F
FireEyeGeneric.mg.20e741dfd69f58db
EmsisoftTrojan.Ransom.VenusLocker (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Crypmod.gv
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1126337
MicrosoftRansom:MSIL/VenusLocker.A
ArcabitGeneric.Ransom.Hiddentear.A.3E1D9874
AegisLabTrojan.Win32.Generic.4!c
GDataMSIL.Trojan-Ransom.Cryptear.L
AhnLab-V3Trojan/Win32.VenusLocker.R192621
McAfeeGenericRXBJ-PZ!20E741DFD69F
MAXmalware (ai score=83)
VBA32Hoax.Crypmod
MalwarebytesMalware.AI.4254121756
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_VENUSLOCK.SM
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.Crypmod!Kd4xaIn/aac
IkarusTrojan-Ransom.HiddenTears
FortinetMSIL/Generic.DN.3682CD!tr
AVGMSIL:Ransom-S [Trj]
Qihoo-360Win32/Ransom.Venus.HwMAEpsA

How to remove Ransom:MSIL/VenusLocker.A?

Ransom:MSIL/VenusLocker.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment