Ransom

What is “Ransom:Win32/Anunau.A”?

Malware Removal

The Ransom:Win32/Anunau.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Anunau.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Attempts to disable Windows Defender
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Anunau.A?


File Info:

crc32: 373A5AED
md5: a82e1e09d8ec9d93795221350871c7b9
name: A82E1E09D8EC9D93795221350871C7B9.mlw
sha1: b4b371d840eb462698a78603b0fbb95371aadbf5
sha256: acbc8ca6b69f1b7098dd4b9567f4d68e4433c72e15e4e43b9fd0211d53ccb5f0
sha512: a3137c8c54802bd96bc5eaf96702958b8356b4a5c6e6c701ca50eeef88947ab91df156cadbec0598eaf497fa8f308f3ac25ea64b3442d8d3e542098f032fe14f
ssdeep: 768:OhDCKeqWnmr95K3p9LRkjgYblzHiblHuVqefyZyiB950WHPnFcjrdccPYi:B9mr95K3plRyrMlOVtiBsYPnMxccAi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Anunau.A also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGeneric.Ransom.Anubis.1DEB6851
CylanceUnsafe
SangforRansom.Win32.Gen.hei
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 00524e521 )
K7AntiVirusTrojan ( 00524e521 )
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.OFL
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.hei
BitDefenderGeneric.Ransom.Anubis.1DEB6851
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGeneric.Ransom.Anubis.1DEB6851
TencentWin32.Trojan.Gen.Llhe
Ad-AwareGeneric.Ransom.Anubis.1DEB6851
SophosML/PE-A
BitDefenderThetaAI:Packer.4C7D57211E
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.qh
FireEyeGeneric.mg.a82e1e09d8ec9d93
EmsisoftGeneric.Ransom.Anubis.1DEB6851 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Gen.sb
AviraHEUR/AGEN.1110387
eGambitUnsafe.AI_Score_77%
Antiy-AVLTrojan/Generic.ASMalwS.2421B19
MicrosoftRansom:Win32/Anunau.A
AegisLabTrojan.Win32.Generic.j!c
ZoneAlarmTrojan-Ransom.Win32.Gen.hei
GDataGeneric.Ransom.Anubis.1DEB6851
AhnLab-V3Trojan/Win32.Ransom.R210473
McAfeeArtemis!A82E1E09D8EC
MAXmalware (ai score=96)
MalwarebytesMalware.AI.2631772674
PandaTrj/CI.A
RisingTrojan.Generic@ML.100 (RDML:FhSiCWBMddNbmM08/Cqokw)
FortinetW32/Filecoder.NNV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Anunau.A?

Ransom:Win32/Anunau.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment