Ransom

Ransom:Win32/Apocalypse information

Malware Removal

The Ransom:Win32/Apocalypse is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Apocalypse virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Detects Sandboxie through the presence of a library
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom:Win32/Apocalypse?


File Info:

crc32: 42449664
md5: a514d3e7892b210ec87ca64d35e6353a
name: A514D3E7892B210EC87CA64D35E6353A.mlw
sha1: 29d7a549132ea35905e8ee6f4d1f53775a602269
sha256: 8c04cfad32ac912512963b81f99d8b8132b54af3f5b25e232e720bc8d68d9709
sha512: b8e50937a5a16676f94d5173ece88b647d56c6b051dbd6bf3a0e2c9e562d293044e1d893beb61a01f45aa95f2286e666ffd5f367357dd6466497f7bf13938dd0
ssdeep: 24576:CgioKTmsLEHbwkM+TFOetVb/bfVqPWFB2g5PrTEztXvct:MoKho7K6VbD9qPaJPutX0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Apocalypse also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00563cb01 )
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.53169
CynetMalicious (score: 100)
ALYacGen:Variant.Jacard.202204
CylanceUnsafe
ZillyaTrojan.Lypserat.Win32.1134
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Bifrose.513d6a1c
K7GWTrojan ( 00563cb01 )
Cybereasonmalicious.7892b2
CyrenW32/Trojan.BRSW-3903
ESET-NOD32a variant of Win32/Lypserat.H
APEXMalicious
AvastWin32:Delf-RDL [Trj]
ClamAVWin.Trojan.Ap0calypseRAT-9806475-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Jacard.202204
NANO-AntivirusTrojan.Win32.Hijacker.ejywgg
MicroWorld-eScanGen:Variant.Jacard.202204
TencentWin32.Trojan.Hijacker.Ljtk
Ad-AwareGen:Variant.Jacard.202204
SophosML/PE-A + Mal/VMProtBad-A
ComodoTrojWare.Win32.Trojan.Generic.28892960@1ulehr
BitDefenderThetaAI:Packer.1B7FBC8C1E
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_BUZUS-3
McAfee-GW-EditionBehavesLike.Win32.PUPXCD.tc
FireEyeGeneric.mg.a514d3e7892b210e
EmsisoftGen:Variant.Jacard.202204 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Hijacker.Gen
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Apocalypse
ArcabitTrojan.Jacard.D315DC
AegisLabWorm.Win32.Fearso.lGmx
GDataGen:Variant.Jacard.202204
AhnLab-V3Backdoor/Win32.Delf.R111296
McAfeeArtemis!A514D3E7892B
MAXmalware (ai score=84)
VBA32BScope.TrojanPSW.Banker
MalwarebytesBackdoor.Bifrose
PandaGeneric Suspicious
TrendMicro-HouseCallMal_BUZUS-3
RisingBackdoor.Apocalypse!1.CB82 (CLOUD)
YandexTrojan.GenAsa!N+bFOD6KFqs
IkarusVirus.Win32.Delf
FortinetW32/Lypserat.H!tr
AVGWin32:Delf-RDL [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Hijacker.HgIASOoA

How to remove Ransom:Win32/Apocalypse?

Ransom:Win32/Apocalypse removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment