Ransom

Ransom:Win32/Bitpaymer removal tips

Malware Removal

The Ransom:Win32/Bitpaymer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Bitpaymer virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Bitpaymer?


File Info:

crc32: ABBF6D50
md5: 2cdf5cc39eaeaf39f6a50c4ef755a04f
name: 2CDF5CC39EAEAF39F6A50C4EF755A04F.mlw
sha1: a1fec5f8edb32d6e147b5229968a4e3e2b0a1806
sha256: 43984eb5b8f35d5e89cebfb755a679b78824dd81a2ecf27829b56ff11cb293cc
sha512: 074f0b893161f04eb65fbdfbc74b28168f7508314ee14d94f4551e83f1b41d356e26abeed5a19a7921f558cb0afb1117fd4a22831020811b6625bf4a06e6db49
ssdeep: 384:DhxwBbmQm/Bz0KSi+1LOUp4WjNHi2CgF:DhWhJijUp4Ui29F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Bitpaymer also known as:

K7AntiVirusTrojan ( 005380eb1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25901
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.Bitpaymer
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.132754
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cryptor.19712933
K7GWTrojan ( 005380eb1 )
Cybereasonmalicious.39eaea
ESET-NOD32Win32/Filecoder.NRI
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Cryptor.bue
BitDefenderTrojan.Ransom.BitPaymer.B
NANO-AntivirusTrojan.Win32.Cryptor.ffbdii
MicroWorld-eScanTrojan.Ransom.BitPaymer.B
TencentMalware.Win32.Gencirc.114d2fec
Ad-AwareTrojan.Ransom.BitPaymer.B
SophosML/PE-A + Troj/BitPay-C
ComodoMalware@#1fxub8u7hrxyd
BitDefenderThetaAI:Packer.42FED9601E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_BITPAYMER.THGABAH
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
FireEyeGeneric.mg.2cdf5cc39eaeaf39
EmsisoftTrojan.Ransom.BitPaymer.B (B)
JiangminTrojan.Cryptor.hj
WebrootW32.Trojan.GenKD
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.27CFF4C
MicrosoftRansom:Win32/Bitpaymer
ArcabitTrojan.Ransom.BitPaymer.B
AegisLabTrojan.Win32.Cryptor.tqOj
GDataTrojan.Ransom.BitPaymer.B
AhnLab-V3Malware/Win32.Ransom_bitpaymer.C2685598
McAfeeGenericRXGI-HM!2CDF5CC39EAE
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Cryptor
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_BITPAYMER.THGABAH
RisingRansom.Crypt!1.A9D3 (CLASSIC)
IkarusTrojan.SuspectCRC
FortinetW32/Filecoder.NRI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Bitpaymer?

Ransom:Win32/Bitpaymer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment