Ransom

Ransom:Win32/Bitpaymer.SA!MSR removal guide

Malware Removal

The Ransom:Win32/Bitpaymer.SA!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Bitpaymer.SA!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

igmp.mcast.net

How to determine Ransom:Win32/Bitpaymer.SA!MSR?


File Info:

crc32: E9F3072E
md5: e6ca85728a9140e0b41aa54e79cde321
name: E6CA85728A9140E0B41AA54E79CDE321.mlw
sha1: 1b09d2068ba1acec013e17e36c8b31eff5d93c3c
sha256: 311d1602323fd826195326ebd0506822f4636f001a0efc940d78922c587ffd96
sha512: 3161966de5a1a41d4e3ec9dcac1eb4c49e599639e1285ed76915f148c2148fd58a04d30e8ad5e39247b926893cece9b8687b88401032862da7db0c0ddfa6c870
ssdeep: 3072:C9m8PZA+tP4itpxya9+ZkzzYKAFfnwGtcQh:eZAEPV8d7Fv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: ADOER15
FileVersion: 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoft Data Access Components
ProductVersion: 2.81.1117.0
FileDescription: Microsoft Data Access - ActiveX Data Objects Resources
OriginalFilename: msader15.dll
Translation: 0x0409 0x04b0

Ransom:Win32/Bitpaymer.SA!MSR also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00549d461 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.28586
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Bitpaymer
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.38594
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/EmotetedCryptc.180910
K7GWTrojan ( 00549d461 )
Cybereasonmalicious.28a914
CyrenW32/Kryptik.AQR.gen!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/Kryptik.GYSK
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.BitPaymer-7373595-0
KasperskyHEUR:Trojan.Win32.DelShad.vho
BitDefenderGen:Variant.Razy.711278
NANO-AntivirusTrojan.Win32.DelShad.gidrrj
ViRobotTrojan.Win32.Z.Bitpaymer.151552
MicroWorld-eScanGen:Variant.Razy.711278
Ad-AwareGen:Variant.Razy.711278
SophosML/PE-A
ComodoMalware@#2j1gzom4sataz
BitDefenderThetaGen:NN.ZexaF.34738.jG0@aC@Au1ci
TrendMicroRansom_Bitpaymer.R002C0DFE21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.e6ca85728a9140e0
EmsisoftGen:Variant.Razy.711278 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1111423
Antiy-AVLTrojan/Generic.ASMalwS.2CFA4AC
MicrosoftRansom:Win32/Bitpaymer.SA!MSR
GDataGen:Variant.Razy.711278
AhnLab-V3Trojan/Win32.RansomCrypt.R355900
Acronissuspicious
McAfeeRansomware-GRI!E6CA85728A91
MAXmalware (ai score=100)
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.BinADS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_Bitpaymer.R002C0DFE21
RisingTrojan.Generic@ML.98 (RDML:LkjIk0qFLcr6e16XXFHZ9g)
YandexTrojan.GenAsa!3YKumlhgVKM
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.74692183.susgen
FortinetW32/DelShad.BOM!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Bitpaymer.SA!MSR?

Ransom:Win32/Bitpaymer.SA!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment