Ransom

Ransom:Win32/BlueScreen (file analysis)

Malware Removal

The Ransom:Win32/BlueScreen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/BlueScreen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (12 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.thesite.org
ocsp.digicert.com
thesite.org
www.bing.com
fonts.googleapis.com
www.googletagmanager.com
cdnjs.cloudflare.com
ocsp.pki.goog
crl.pki.goog
crls.pki.goog
fonts.gstatic.com

How to determine Ransom:Win32/BlueScreen?


File Info:

crc32: B4FB6437
md5: 4d762a773b0a4bce509d5b52e11d6fa2
name: 4D762A773B0A4BCE509D5B52E11D6FA2.mlw
sha1: 74f1c579aed2d2609ce11054d17d02786e3af43e
sha256: da66fce06534b20c0c95e3ba1d2ce05767a7b81b2a714a80be1f163453214d2e
sha512: 357f24300bc2ed537d53f0e86abbaef1c155f5a4c21b2bf3c01e192c5b9a1d0ea11d884cd81de65d73fab589faf5be66ddccd255f7137b539ebcbc52edbd4a2a
ssdeep: 6144:Xxws8r4/+r4sgDMatGLcKUHFf7hgloxBbejEn7u0WC:XxC844zsLclHFpzbt7pW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/BlueScreen also known as:

BkavW32.AIDetect.malware2
DrWebWin32.HLLW.Jobaka.137
CylanceUnsafe
ZillyaAdware.BargainBuddy.Win32.200
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/BlueScreen.a6fe844b
SymantecML.Attribute.HighConfidence
AvastWin32:Malware-gen
NANO-AntivirusTrojan.Win32.Jobaka.eyycqj
ViRobotTrojan.Win32.A.Diamin.57336
ComodoMalware@#t37j2p3u4u9e
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_UNRUY.LPX
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.4d762a773b0a4bce
JiangminTrojan/JboxGeneric.bff
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_89%
Antiy-AVLTrojan/Generic.ASBOL.C678
KingsoftWin32.Malware.Heur_Generic.A.(kcloud)
MicrosoftRansom:Win32/BlueScreen
AegisLabTrojan.Win32.Generic.4!c
McAfeeArtemis!4D762A773B0A
VBA32Worm.Sasser
MalwarebytesMachineLearning/Anomalous.93%
TrendMicro-HouseCallTROJ_UNRUY.LPX
RisingTrojan.Win32.Dialer.uoi (CLASSIC)
YandexTrojan.GenAsa!KKFl4EcJwr8
FortinetW32/Jobaka.HLLW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/BlueScreen?

Ransom:Win32/BlueScreen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment