Ransom

Ransom:Win32/Ciluf removal tips

Malware Removal

The Ransom:Win32/Ciluf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Ciluf virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Windows Defender AV emulator via files
  • Harvests cookies for information gathering
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Ransom:Win32/Ciluf?


File Info:

name: 7C10CF39EE3169BB3E46.mlw
path: /opt/CAPEv2/storage/binaries/007c1f11afb195d77c176891d54b9cfd37c87b13dfe0ab5b6c368125e4459b8c
crc32: 643A0101
md5: 7c10cf39ee3169bb3e46aac14c888228
sha1: e3902bc1f576ad063db6da455a820a840c1556a4
sha256: 007c1f11afb195d77c176891d54b9cfd37c87b13dfe0ab5b6c368125e4459b8c
sha512: c57809d6ea2ad764a7479939780d3af00d3bff9ff155b8d0e563b780be794124831e0cc6eacd31c0ebee8d26358c48aeeed59e94ca6f419defa9e5c30f67644e
ssdeep: 98304:2KbdBAEoDCqpmeSInsYSo5QAXZx7SnqS5pX6qXNhsubdf5gEbvU0C5WsYjRBJ:LvxCzWIsYSSQ+xNEpT5f5JvoWsoRB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C466330BF6F24833E8721737B8F2E176BD2FF424072A95C78B45286946593D53AB9309
sha3_384: 347c8b17381687c9b7672513ebfee542327e711085f866281e148d1c77c4b2e5c24dcc5ead529ef90fbee08d7aab9fb4
ep_bytes: e836050000e98efeffffcccccc575653
timestamp: 2017-07-31 15:20:53

Version Info:

0: [No Data]

Ransom:Win32/Ciluf also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Gen.j!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.6266432
FireEyeGeneric.mg.7c10cf39ee3169bb
CAT-QuickHealRansom.Halloware.S1855861
ALYacTrojan.Ransom.Halloware
CylanceUnsafe
VIPRETrojan.GenericKD.6266432
SangforRansom.Win32.Gen.gch
K7AntiVirusTrojan ( 0051f3991 )
AlibabaRansom:Win32/Ciluf.f6ea216d
K7GWTrojan ( 0051f3991 )
Cybereasonmalicious.9ee316
CyrenW32/Halloware.FOLM-1042
SymantecTrojan.Seaduke
ESET-NOD32Win32/Filecoder.NOO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Gen.gch
BitDefenderTrojan.GenericKD.6266432
NANO-AntivirusTrojan.Win32.Encoder.evofds
AvastFileRepMalware [Trj]
Ad-AwareTrojan.GenericKD.6266432
EmsisoftTrojan.GenericKD.6266432 (B)
ComodoMalware@#2nzujrzh6k6pj
DrWebTrojan.Encoder.19344
TrendMicroRansom_HALLOWARE.A
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-R + Troj/Ransom-ETL
GDataTrojan.GenericKD.6266432
WebrootW32.Trojan.GenKD
AviraTR/DelFile.pxvju
Antiy-AVLTrojan/Generic.ASMalwS.474C
ViRobotTrojan.Win32.S.Halloware.6542330
ZoneAlarmTrojan-Ransom.Win32.Gen.gch
MicrosoftRansom:Win32/Ciluf
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Gen
McAfeeRansom-O.h
MAXmalware (ai score=100)
VBA32TrojanRansom.Gen
TrendMicro-HouseCallRansom_HALLOWARE.A
TencentWin32.Trojan.Filecoder.Ahoi
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.74367540.susgen
FortinetW32/Gen.GCH!tr
AVGFileRepMalware [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/Ciluf?

Ransom:Win32/Ciluf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment