Ransom

Should I remove “Ransom:Win32/Egregor.BM!MSR”?

Malware Removal

The Ransom:Win32/Egregor.BM!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Egregor.BM!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Egregor.BM!MSR?


File Info:

crc32: 09A45B2D
md5: c4b4f95c3dd6d9170858735f963b6fc3
name: C4B4F95C3DD6D9170858735F963B6FC3.mlw
sha1: a29fc0eb58ad97e29171a2a5c5011a1bf4f16304
sha256: 311baa4d4229a8d6802d82a8d9935592bf9a7b6aaf0949f0fa0b094592f5e8a7
sha512: 5de23f76f8cf5df6490404a6da26af4047484f62e2e7b6839308bf1e28fd226ccc5eb8c463d96004e222852bb735749754b61dd589986baf0ce0251977571772
ssdeep: 12288:2P9Fk91nFoMWTbxUW/y56Tsf0zGeUsmyVi5MCdA80KjAJp:2fs9KLUxSqAf
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Egregor.BM!MSR also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.Encoder.32897
MicroWorld-eScanGen:Variant.Zusy.325870
CAT-QuickHealTrojan.Bsymem
Qihoo-360Win32/Trojan.1ce
McAfeeRansom-Egregor!C4B4F95C3DD6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Bsymem.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderGen:Variant.Zusy.325870
K7GWTrojan ( 00571ac01 )
K7AntiVirusTrojan ( 00571ac01 )
ArcabitTrojan.Zusy.D4F8EE
SymantecTrojan Horse
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.Win32.Generic
AlibabaRansom:Win32/Egregor.7417cbce
NANO-AntivirusTrojan.Win32.Bsymem.iawcwn
ViRobotTrojan.Win32.Z.Zusy.786944.F
RisingTrojan.Kryptik!8.8 (TFE:5:Gn9Vn3cQ3xN)
Ad-AwareGen:Variant.Zusy.325870
SophosMal/Generic-R + Mal/Sekhmet-A
F-SecureTrojan.TR/Crypt.Agent.zxlgs
ZillyaTrojan.Kryptik.Win32.2615313
TrendMicroRansom.Win32.EGREGOR.SMYAAK-J
McAfee-GW-EditionRansom-Egregor!C4B4F95C3DD6
FireEyeGen:Variant.Zusy.325870
EmsisoftGen:Variant.Zusy.325870 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Bsymem.aip
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.zxlgs
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Egregor.BM!MSR
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Variant.Zusy.325870
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R354842
VBA32Trojan.Bsymem
ALYacTrojan.Ransom.Egregor
MalwarebytesRansom.Sekhmet
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HGXV
TrendMicro-HouseCallRansom.Win32.EGREGOR.SMYAAK-J
TencentWin32.Trojan.Bsymem.Szbg
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HGHT!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.73746529.susgen

How to remove Ransom:Win32/Egregor.BM!MSR?

Ransom:Win32/Egregor.BM!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment