Ransom

How to remove “Ransom:Win32/Guperd”?

Malware Removal

The Ransom:Win32/Guperd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Guperd virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
jmqapf3nflatei35.onion.link

How to determine Ransom:Win32/Guperd?


File Info:

crc32: CD0A209A
md5: a518b08c6fb4fd2c354517e4a5968a41
name: A518B08C6FB4FD2C354517E4A5968A41.mlw
sha1: acad64b13c31f2ed52021696514abf8640baeda7
sha256: 3e06ef992519c02f43b10cc9bfa671e5176e2cef5fab2f3d21b1e7fc17438e7d
sha512: ec7b0451a20235cd79235d2bedbe480aaff7bd37e01eb768dfc1bd7c3bc91e8f430adc434e2b6670bb0ed409a1f42a250b1e2fcab4f0c613d76099bdba54c9f9
ssdeep: 1536:sDttzTGhByLDQdv8/sSgTn980Rw9Q50cI6rA5jR/cRzk:mtZTG3yAdv8/sSgz980CQC56rA5jORz
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Guperd also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00524a071 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24356
CynetMalicious (score: 99)
ALYacTrojan.Ransom.MoneroPay
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7005
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:Win32/Guperd.e040ca19
K7GWTrojan ( 00524a071 )
Cybereasonmalicious.c6fb4f
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.MoneroPay.B
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.MoneroPay.9B1B6606
NANO-AntivirusTrojan.Win32.RedCap.exegmy
ViRobotTrojan.Win32.Ransom.74240.F
MicroWorld-eScanGeneric.Ransom.MoneroPay.9B1B6606
TencentWin32.Trojan.Filecoder.Ljto
Ad-AwareGeneric.Ransom.MoneroPay.9B1B6606
SophosMal/Generic-S + Troj/XMRPay-A
BitDefenderThetaAI:Packer.5175D6341E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MONEROPAY.THAOOAI
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
FireEyeGeneric.Ransom.MoneroPay.9B1B6606
EmsisoftGeneric.Ransom.MoneroPay.9B1B6606 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bwmuy
WebrootW32.Trojan.Gen
AviraTR/Redcap.bwbhh
Antiy-AVLTrojan/Generic.ASMalwS.23DB357
MicrosoftRansom:Win32/Guperd
GDataGeneric.Ransom.MoneroPay.9B1B6606
AhnLab-V3Trojan/Win32.Ransom.C2374769
McAfeeRansomware-GJN!A518B08C6FB4
MAXmalware (ai score=95)
VBA32TrojanRansom.Guperd
MalwarebytesRansom.Monero
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_MONEROPAY.THAOOAI
RisingTrojan.Guperd!1.A539 (CLASSIC)
YandexTrojan.Agent!93ulmaGoiMU
IkarusTrojan-Ransom.Guperd
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Miner.Monero.HxQB2NUA

How to remove Ransom:Win32/Guperd?

Ransom:Win32/Guperd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment